{
    "type": "bundle",
    "id": "bundle--a4ed2a8b-a22b-4905-b83d-c95b50ee1296",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.093218Z",
            "modified": "2026-06-14T11:56:06.093218Z",
            "name": "The Hunters Ledger",
            "identity_class": "organization"
        },
        {
            "type": "marking-definition",
            "spec_version": "2.1",
            "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
            "created": "2017-01-20T00:00:00.000Z",
            "definition_type": "tlp",
            "name": "TLP:WHITE",
            "definition": {
                "tlp": "white"
            }
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--d0692743-5b00-5146-a398-5e94b76ad3ad",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.093902Z",
            "modified": "2026-06-14T11:56:06.093902Z",
            "name": "SogouStealer masquerading NSIS installer execution",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: SogouStealer masquerading NSIS installer execution\nid: 7e3c7c1c-7b4a-4f5e-9c0a-ss-nsis-sogou\nstatus: stable\ndescription: Detects execution of suspected NSIS-based fake Sogou installers with cracked-build markers\nreferences: []\ntags:\n  - attack.initial_access\n  - attack.t1036\nlogsource:\n  product: windows\n  category: process_creation\ndetection:\n  selection_image:\n    Image|endswith:\n      - '\\installer.exe'\n      - '\\setup.exe'\n      - '\\install.exe'\n  selection_cmdline:\n    CommandLine|contains:\n      - 'NSIS'\n      - 'Nullsoft'\n      - 'Sogou'\n      - '\u62fc\u97f3'\n      - '\u543e\u7231\u7834\u89e3'\n      - 'v15.1.0.1570'\n  condition: selection_image and selection_cmdline\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--b0a4440b-05f8-5413-8de0-16033de7dc04",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.094153Z",
            "modified": "2026-06-14T11:56:06.094153Z",
            "name": "SogouStealer persistence via Run keys and LNK modification",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: SogouStealer persistence via Run keys and LNK modification\nid: 1f2b5f1a-1d0b-4c84-8e2b-ss-persist-run-lnk\nstatus: stable\ndescription: Detects registry Run key entries and .lnk modifications pointing to %AppData% or %Temp%\ntags:\n  - attack.persistence\n  - attack.t1547.001\n  - attack.t1547.009\nlogsource:\n  product: windows\n  category: registry_set\ndetection:\n  selection_run:\n    TargetObject|contains:\n      - '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run'\n      - '\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce'\n    Details|contains:\n      - '\\AppData\\'\n      - '\\Temp\\'\n      - '.lnk'\n  condition: selection_run\nlevel: high\nfields:\n  - TargetObject\n  - Details",
            "pattern_type": "sigma",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--a689d607-2f63-5d64-afc0-c29b0fb0afce",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.094309Z",
            "modified": "2026-06-14T11:56:06.094309Z",
            "name": "SogouStealer artifact drop and staging",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: SogouStealer artifact drop and staging\nid: 9d9e1a86-5c6d-4b82-9b89-ss-file-artifacts\nstatus: stable\ndescription: Detects creation of known components used by the malware ecosystem\ntags:\n  - attack.execution\n  - attack.defense_evasion\n  - attack.persistence\nlogsource:\n  product: windows\n  category: file_create\ndetection:\n  selection_names:\n    TargetFilename|endswith:\n      - '\\beacon_sdk.dll'\n      - '\\SGDownload.exe'\n      - '\\SGCurlHelper.dll'\n      - '\\userNetSchedule.exe'\n      - '\\UserExportDll.dll'\n      - '\\UrlSignatureV.dat'\n      - '\\pandorabox.cupf'\n      - '\\PersonalCenter.cupf'\n  condition: selection_names\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--8ef962e8-d673-5b96-88c9-00e670f79a22",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.094462Z",
            "modified": "2026-06-14T11:56:06.094462Z",
            "name": "Potential access token manipulation by suspicious installer",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Potential access token manipulation by suspicious installer\nid: 0c7b42ef-0c62-4a36-9e33-ss-token-manipulation\nstatus: experimental\ndescription: Flags sensitive privilege assignments indicative of token manipulation\ntags:\n  - attack.privilege_escalation\n  - attack.t1134\nlogsource:\n  product: windows\n  category: process_access\ndetection:\n  selection:\n    GrantedAccess|contains:\n      - '0x1FFFFF'\n      - '0x00100000'\n    CallTrace|contains:\n      - 'OpenProcessToken'\n      - 'AdjustTokenPrivileges'\n  condition: selection\nlevel: medium",
            "pattern_type": "sigma",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--61ad49ad-14fc-5169-8cc7-68c6834de287",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.094606Z",
            "modified": "2026-06-14T11:56:06.094606Z",
            "name": "DNS queries for SogouStealer disposable domains",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: DNS queries for SogouStealer disposable domains\nid: 8f4b2c6e-0c9a-4f5a-9a55-ss-dns-iocs\nstatus: stable\ndescription: Detects DNS lookups for known C2 domains decoded from config\ntags:\n  - attack.command_and_control\n  - attack.t1071.001\nlogsource:\n  product: windows\n  category: dns_query\ndetection:\n  selection_domains:\n    QueryName|endswith:\n      - '6.ar'\n      - 'j.im'\n      - '5bng.ar'\n      - 'b.tk'\n      - 'k.ct'\n      - 'q.ar'\n      - 'rlh.cq'\n      - 's0.ndf'\n      - 'vpl.gu'\n      - 'x.pg'\n  condition: selection_domains\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--0ca280d6-a10b-500b-9fcb-9e1135d5091d",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.094747Z",
            "modified": "2026-06-14T11:56:06.094747Z",
            "name": "Network connections to known C2 IPs (Argentina Donweb & AWS Ashburn)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "title: Network connections to known C2 IPs (Argentina Donweb & AWS Ashburn)\nid: 2b0ecf3e-8a49-4d44-9fd9-ss-net-c2-ips\nstatus: stable\ndescription: Detects connections to IPs associated with disposable infrastructure used by the malware\ntags:\n  - attack.command_and_control\n  - attack.t1071.001\nlogsource:\n  product: windows\n  category: network_connection\ndetection:\n  selection_ips:\n    DestinationIp:\n      - '149.50.136.243'\n      - '52.20.84.62'\n  condition: selection_ips\nlevel: high",
            "pattern_type": "sigma",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--ed0dac53-9969-5480-a878-8f56a11c5d05",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.094952Z",
            "modified": "2026-06-14T11:56:06.094952Z",
            "name": "SogouStealer_Ecosystem_Indicators",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "rule SogouStealer_Ecosystem_Indicators\n{\n  meta:\n    description = \"Detects SogouStealer ecosystem by domains, token markers, and API strings\"\n    author = \"The Hunters Ledger\"\n    reference = \"Hunter\u2019s Ledger investigation\"\n    date = \"2025-11-21\"\n  strings:\n    // Domains and token\n    $d1 = \"6.ar\" ascii nocase\n    $d2 = \"J.im\" ascii nocase\n    $d3 = \"5bNG.ar\" ascii nocase\n    $d4 = \"B.tk\" ascii nocase\n    $d5 = \"K.ct\" ascii nocase\n    $d6 = \"Q.ar\" ascii nocase\n    $d7 = \"rlh.cq\" ascii nocase\n    $d8 = \"s0.ndf\" ascii nocase\n    $d9 = \"vpl.gu\" ascii nocase\n    $d10 = \"X.pg\" ascii nocase\n    $tok = \"CGI1\" ascii\n\n    // Masquerade & Sogou endpoints used for disguise\n    $s1 = \"Sogou Input Method v15.1.0.1570\" wide ascii\n    $s2 = \"get.sogou.com\" ascii\n    $s3 = \"ping.pinyin.sogou.com\" ascii\n\n    // NSIS and packing indicators\n    $n1 = \"Nullsoft\" ascii\n    $n2 = \"NSIS\" ascii\n    $enc1 = \"CRC32\" ascii\n    $enc2 = \"XOR\" ascii\n\n    // Anti-analysis and persistence-related APIs\n    $api1 = \"FindWindowExA\" ascii\n    $api2 = \"GetLastError\" ascii\n    $api3 = \"IShellLink\" ascii\n    $vm1  = \"Xen\" ascii\n\n    // Component names\n    $f1 = \"beacon_sdk.dll\" ascii\n    $f2 = \"SGDownload.exe\" ascii\n    $f3 = \"SGCurlHelper.dll\" ascii\n    $f4 = \"userNetSchedule.exe\" ascii\n    $f5 = \"UserExportDll.dll\" ascii\n    $f6 = \"UrlSignatureV.dat\" ascii\n    $f7 = \"pandorabox.cupf\" ascii\n    $f8 = \"PersonalCenter.cupf\" ascii\n  condition:\n    uint16(0) == 0x5A4D and\n    ( ($d1 or $d2) or (2 of ($d3,$d4,$d5,$d6,$d7,$d8,$d9,$d10)) ) and\n    ( 2 of ($api1,$api2,$api3,$vm1,$n1,$n2,$enc1,$enc2,$tok) ) and\n    ( 1 of ($f1,$f2,$f3,$f4,$f5,$f6,$f7,$f8) )\n}",
            "pattern_type": "yara",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--9aa75bc9-fb08-5da9-a63f-922bed543b59",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.095096Z",
            "modified": "2026-06-14T11:56:06.095096Z",
            "name": "SogouStealer_Loader_Downloader",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "rule SogouStealer_Loader_Downloader\n{\n  meta:\n    description = \"Detects packed loader and downloader components\"\n    author = \"The Hunters Ledger\"\n    date = \"2025-11-21\"\n  strings:\n    $loader = \"beacon_sdk.dll\" ascii\n    $down   = \"SGDownload.exe\" ascii\n    $anti1  = \"IsDebuggerPresent\" ascii\n    $anti2  = \"QueryPerformanceCounter\" ascii\n    $pack1  = \"overlay\" ascii\n  condition:\n    uint16(0) == 0x5A4D and\n    ( $loader or $down ) and\n    ( 1 of ($anti1,$anti2) )\n}",
            "pattern_type": "yara",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--f982d887-c5c8-574e-b7e0-d3f07e012866",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.095262Z",
            "modified": "2026-06-14T11:56:06.095262Z",
            "name": "SogouStealer_C2_Scheduler_SignatureDB",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "rule SogouStealer_C2_Scheduler_SignatureDB\n{\n  meta:\n    description = \"Detects scheduler, networking helpers, and URL signature database\"\n    author = \"The Hunters Ledger\"\n    date = \"2025-11-21\"\n  strings:\n    $sched = \"userNetSchedule.exe\" ascii\n    $curl  = \"SGCurlHelper.dll\" ascii\n    $sigdb = \"UrlSignatureV.dat\" ascii\n    $cgi   = \"/cgi1\" ascii\n  condition:\n    uint16(0) == 0x5A4D and ( $sched or $curl ) or $sigdb or $cgi\n}",
            "pattern_type": "yara",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--ce520617-ecc0-5870-afe2-d5ba78b8791a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.09555Z",
            "modified": "2026-06-14T11:56:06.09555Z",
            "name": "SogouStealer IOC - DNS query for 6.ar",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for 6.ar\"; dns.query; content:\"6.ar\"; nocase; classtype:trojan-activity; sid:700001; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for j.im\"; dns.query; content:\"j.im\"; nocase; classtype:trojan-activity; sid:700002; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"5bng.ar\"; nocase; classtype:trojan-activity; sid:700003; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"b.tk\"; nocase; classtype:trojan-activity; sid:700004; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"k.ct\"; nocase; classtype:trojan-activity; sid:700005; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"q.ar\"; nocase; classtype:trojan-activity; sid:700006; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"rlh.cq\"; nocase; classtype:trojan-activity; sid:700007; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"s0.ndf\"; nocase; classtype:trojan-activity; sid:700008; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"vpl.gu\"; nocase; classtype:trojan-activity; sid:700009; rev:1;)\nalert dns any any -> any any (msg:\"SogouStealer IOC - DNS query for disposable domains\"; dns.query; content:\"x.pg\"; nocase; classtype:trojan-activity; sid:700010; rev:1;)",
            "pattern_type": "suricata",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--63cec5ef-9a73-52cd-869c-1729eaec074a",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.095836Z",
            "modified": "2026-06-14T11:56:06.095836Z",
            "name": "SogouStealer IOC - TLS SNI 6.ar",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert tls any any -> any any (msg:\"SogouStealer IOC - TLS SNI 6.ar\"; tls.sni; content:\"6.ar\"; nocase; classtype:trojan-activity; sid:700020; rev:1;)\nalert tls any any -> any any (msg:\"SogouStealer IOC - TLS SNI j.im\"; tls.sni; content:\"j.im\"; nocase; classtype:trojan-activity; sid:700021; rev:1;)",
            "pattern_type": "suricata",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--e2d628d2-65c0-5775-9abb-51a6e4467a9c",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.096057Z",
            "modified": "2026-06-14T11:56:06.096057Z",
            "name": "SogouStealer IOC - HTTP Host 6.ar",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert http any any -> any any (msg:\"SogouStealer IOC - HTTP Host 6.ar\"; http.host; content:\"6.ar\"; nocase; classtype:trojan-activity; sid:700030; rev:1;)\nalert http any any -> any any (msg:\"SogouStealer IOC - HTTP Host j.im\"; http.host; content:\"j.im\"; nocase; classtype:trojan-activity; sid:700031; rev:1;)\nalert http any any -> any any (msg:\"SogouStealer IOC - HTTP URI contains /cgi1\"; http.uri; content:\"/cgi1\"; nocase; classtype:trojan-activity; sid:700032; rev:1;)",
            "pattern_type": "suricata",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "indicator",
            "spec_version": "2.1",
            "id": "indicator--b4121ddb-9e41-5893-8297-245b23142118",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.096273Z",
            "modified": "2026-06-14T11:56:06.096273Z",
            "name": "SogouStealer IOC - Traffic to 149.50.136.243 (Donweb)",
            "indicator_types": [
                "malicious-activity"
            ],
            "pattern": "alert ip any any -> 149.50.136.243 any (msg:\"SogouStealer IOC - Traffic to 149.50.136.243 (Donweb)\"; classtype:trojan-activity; sid:700040; rev:1;)\nalert ip any any -> 52.20.84.62 any (msg:\"SogouStealer IOC - Traffic to 52.20.84.62 (AWS Ashburn)\"; classtype:trojan-activity; sid:700041; rev:1;)",
            "pattern_type": "suricata",
            "valid_from": "2025-11-21T00:00:00Z",
            "labels": [
                "detection-rule"
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--60de42bf-6fb0-59f8-8f0b-67e8bf184aaf",
            "created_by_ref": "identity--8bc8284b-deb5-546c-a233-57ea34b2ea0d",
            "created": "2026-06-14T11:56:06.096824Z",
            "modified": "2026-06-14T11:56:06.096824Z",
            "name": "Hybrid Ecosystem Masquerading as Sogou",
            "report_types": [
                "threat-report"
            ],
            "published": "2025-11-21T00:00:00Z",
            "object_refs": [
                "indicator--d0692743-5b00-5146-a398-5e94b76ad3ad",
                "indicator--b0a4440b-05f8-5413-8de0-16033de7dc04",
                "indicator--a689d607-2f63-5d64-afc0-c29b0fb0afce",
                "indicator--8ef962e8-d673-5b96-88c9-00e670f79a22",
                "indicator--61ad49ad-14fc-5169-8cc7-68c6834de287",
                "indicator--0ca280d6-a10b-500b-9fcb-9e1135d5091d",
                "indicator--ed0dac53-9969-5480-a878-8f56a11c5d05",
                "indicator--9aa75bc9-fb08-5da9-a63f-922bed543b59",
                "indicator--f982d887-c5c8-574e-b7e0-d3f07e012866",
                "indicator--ce520617-ecc0-5870-afe2-d5ba78b8791a",
                "indicator--63cec5ef-9a73-52cd-869c-1729eaec074a",
                "indicator--e2d628d2-65c0-5775-9abb-51a6e4467a9c",
                "indicator--b4121ddb-9e41-5893-8297-245b23142118"
            ],
            "labels": [
                "Loader",
                "Stealer",
                "Cred Theft",
                "Evasion"
            ],
            "external_references": [
                {
                    "source_name": "The Hunters Ledger",
                    "url": "https://the-hunters-ledger.com/reports/Hybrid-Loader-Stealer-Sogou/"
                }
            ],
            "object_marking_refs": [
                "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
            ]
        }
    ]
}