{
  "Event": {
    "analysis": "1",
    "date": "2026-04-15",
    "extends_uuid": "",
    "info": "[Threat Intel] From fake Proton VPN sites to gaming mods, this Windows infostealer is everywhere",
    "protected": false,
    "publish_timestamp": "1776767210",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1776767210",
    "uuid": "aa93eeb2-ef93-463d-a1fe-c6ca54d01353",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#0cb256",
        "local": false,
        "name": "misp-galaxy:producer=\"Malwarebytes\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#f146c3",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Sharepoint - T1213.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#ed66f6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#75ec20",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Masquerading - T1036\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#3b96ed",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"CMSTP - T1218.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#8ed4a7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#3780c6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b95cd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4bc785",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#356c41",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Drive-by Compromise - T1189\"",
        "relationship_type": ""
      },
      {
        "colour": "#fdd85e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776682809",
        "to_ids": false,
        "type": "link",
        "uuid": "55b7b7e2-8501-48d0-90b6-53a8e3ab1808",
        "value": "https://www.malwarebytes.com/blog/threat-intel/2026/04/from-fake-proton-vpn-sites-to-gaming-mods-this-windows-infostealer-is-everywhere"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776682809",
        "to_ids": false,
        "type": "text",
        "uuid": "d61651fa-2f2a-42f6-9971-3b5c0cd51d52",
        "value": "Multiple campaigns are distributing NWHStealer through diverse delivery methods including fake VPN downloads, hardware utilities, and gaming modifications. The malware collects browser data, saved passwords, and cryptocurrency wallet information. Distribution occurs via fake websites impersonating legitimate services like Proton VPN, code hosting platforms such as GitHub and GitLab, file hosting services including MediaFire and SourceForge, and links from YouTube videos. Two primary infection methods were identified: one using a free web hosting provider distributing malicious ZIP files with self-injection, and another using fake websites with DLL hijacking that injects code into RegAsm processes. The stealer targets over 25 cryptocurrency wallets and multiple browsers, using AES-CBC encryption for command-and-control communications and employing UAC bypass techniques for privilege escalation."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776682809",
        "to_ids": false,
        "type": "text",
        "uuid": "c33ab948-7747-46aa-b650-398398650554",
        "value": "Name: From fake Proton VPN sites to gaming mods, this Windows infostealer is everywhere\nAuthor: AlienVault\nAdversary: \nTags: [\"nwhstealer\", \"fake vpn\", \"dll hijacking\", \"infostealer\", \"process injection\", \"cryptocurrency wallet theft\", \"browser data theft\", \"uac bypass\"]\nTgtd countries: []\nMlwr families: [\"NWHStealer\"]\nAttack_ids: [\"T1053.005\", \"T1213.002\", \"T1539\", \"T1082\", \"T1005\", \"T1140\", \"T1036\", \"T1055\", \"T1218.003\", \"T1112\", \"T1555.003\", \"T1204\", \"T1566\", \"T1562.001\", \"T1055.012\", \"T1027\", \"T1573\", \"T1189\", \"T1134\", \"T1071.001\"]\nIndustries: []"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776696504",
        "to_ids": true,
        "type": "domain",
        "uuid": "6d1db50e-304c-44f5-8100-ff8d81f38138",
        "value": "get-proton-vpn.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776696526",
        "to_ids": true,
        "type": "domain",
        "uuid": "1647e8b3-e726-4b1c-8463-cb9fd785e4b1",
        "value": "vpn-proton-setup.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776696547",
        "to_ids": true,
        "type": "domain",
        "uuid": "375237d9-7375-4501-9647-d75868b8042d",
        "value": "newworld-helloworld.icu",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776696568",
        "to_ids": true,
        "type": "url",
        "uuid": "3fa4d5ed-c34b-485a-bbb8-ff8beded3777",
        "value": "https://www.onworks.net/software/windows/app-hardware-visualizer",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776696589",
        "to_ids": true,
        "type": "url",
        "uuid": "3c6a6e80-5164-4814-9d3a-a6d772d71401",
        "value": "https://t.me/gerj_threuh",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776696611",
        "to_ids": true,
        "type": "url",
        "uuid": "ecbed721-2e68-4f52-a54f-0743440d267f",
        "value": "https://sourceforge.net/projects/sidebar-diagnostics/files/Sidebar%20Diagnostics-3.6.5.zip",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1776696633",
        "to_ids": true,
        "type": "url",
        "uuid": "c4cacf39-1fe1-4b4b-bf10-b952d18af2bd",
        "value": "https://github.com/PieceHydromancer/Lossless-Scaling-v3.22-Windows-Edition/releases/download/Fps/Lossless.Scaling.v3.22.zip",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1776696654",
        "uuid": "68a5638b-8a74-4798-8ecc-67e2ea38578f",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1776696654",
            "to_ids": true,
            "type": "md5",
            "uuid": "d0a8cc62-28ba-4916-a140-bfb73610d68b",
            "value": "5cb3b902ae5993ae4e502f1c29cfb4e0",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1776692137",
            "to_ids": true,
            "type": "sha1",
            "uuid": "f97d9d14-50b6-4d7d-9fde-e6548c60d806",
            "value": "8ef6bcde887786d1a96497fa9aa04fd4e1eb02b0",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1776692137",
            "to_ids": true,
            "type": "sha256",
            "uuid": "945f3392-1d7a-430b-9592-1a2006fd0977",
            "value": "2494709b8a2646640b08b1d5d75b6bfb3167540ed4acdb55ded050f6df9c53b3",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1776691711",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "f5951ef9-95a8-4fa7-bfcb-56573c7ac553",
            "value": "98304:KaduqglAwC1OtQWZlox9qivrBAtlCIz2oNmNvbUh13/3Kf2Zmdv0dHWgPa:KAudAvYtXGx9qm2lOFbUhVPXecd2gP"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1776691712",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "c8e9b734-3d82-46a7-9650-0f5c63fb73ea",
            "value": "5658624"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1776691712",
            "to_ids": true,
            "type": "vhash",
            "uuid": "de51a94c-fafe-4f02-8ded-9ea14a0fc41a",
            "value": "1560b65d1555551c05151az3e38&z1"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1776691712",
            "to_ids": true,
            "type": "filename",
            "uuid": "44bedcd1-12dc-485e-9d56-7604f938bb2f",
            "value": "WindowsCodecs.dll"
          },
          {
            "category": "Other",
            "comment": "Checked: 20/04/2026\nLast-scan\t:  17/04/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1776691712",
            "to_ids": false,
            "type": "text",
            "uuid": "a96f0aaf-248b-4fdd-ad0a-2be8eade0d79",
            "value": "Type Description: Win32 DLL\nMicrosoft: Trojan:Win32/Kepavll!rfn\nVT Total Detection:49/72\nFirst Submission:2026-03-09T16:58:18.000000+00:00\nLast Submission:2026-03-09T16:58:18.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1776696675",
        "uuid": "04931542-1505-4df4-ab40-cc1282c60f41",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1776696675",
            "to_ids": true,
            "type": "md5",
            "uuid": "a18fe440-0f56-4a05-882a-bb0cfc01ceac",
            "value": "15b2bb2a3d57e2553ff79a7e47101550",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1776692138",
            "to_ids": true,
            "type": "sha1",
            "uuid": "074ec587-a26e-4130-888a-66fca87751ab",
            "value": "eaa4260a222b6cf41fb9033a8f3ee213ce85983f",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1776692138",
            "to_ids": true,
            "type": "sha256",
            "uuid": "534139d9-b0a6-416d-871e-26a6772f456d",
            "value": "e97cb6cbcf2583fe4d8dcabd70d3f67f6cc977fc9a8cbb42f8a2284efe24a1e3",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1776691733",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "9d81ba12-7cb0-4379-a622-74f79832d223",
            "value": "786432:KbJUzX3fukuJR++EN6IRG4+ozV32Yc3Edi4n6g4:nj3fukM+vN6iQ0MYglvg4"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1776691733",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "dc3d8760-3623-4207-b2dd-e57c3b870da5",
            "value": "30308935"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1776691733",
            "to_ids": true,
            "type": "vhash",
            "uuid": "1637487e-0ef7-426b-84ab-b1bba787832c",
            "value": "cfaee718530d4b1f4c67fbdb405fe888"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1776691733",
            "to_ids": true,
            "type": "filename",
            "uuid": "5898f0e5-60b3-4026-8bc4-ba934c6262a6",
            "value": "HardwareVisualizer_1.3.1.zip"
          },
          {
            "category": "Other",
            "comment": "Checked: 20/04/2026\nLast-scan\t:  18/04/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1776691733",
            "to_ids": false,
            "type": "text",
            "uuid": "83b3e4d7-f82a-4ff4-8f34-58f9d236db44",
            "value": "Type Description: ZIP\nMicrosoft: None\nVT Total Detection:40/69\nFirst Submission:2026-03-12T19:19:05.000000+00:00\nLast Submission:2026-03-12T19:19:05.000000+00:00"
          }
        ]
      }
    ]
  }
}