{"id":"T1070","name":"Indicator Removal","url":"https://attack.mitre.org/techniques/T1070","tactics":["stealth"],"platforms":["Containers","ESXi","Linux","macOS","Network Devices","Office Suite","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0184","stix_id":"x-mitre-detection-strategy--7225a3bd-f235-4c13-a236-3c6b9a3d445c","name":"Behavioral Detection of Indicator Removal Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0184","analytics":[{"id":"AN0520","stix_id":"x-mitre-analytic--4416c78b-902b-4baa-9a5d-26f0b7e5d78d","name":"Analytic 0520","description":"Monitors sequences involving deletion/modification of logs, registry keys, scheduled tasks, or prefetch files following suspicious process activity or elevated access escalation.","url":"https://attack.mitre.org/detectionstrategies/DET0184#AN0520","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=23","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=1102","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlate indicator removal within X mins after persistence/setup activities"},{"field":"TargetFilePathPattern","description":"Customize detection to log file paths or common registry hives"}],"live":true,"detection_strategies":["DET0184"],"techniques":["T1070"]},{"id":"AN0521","stix_id":"x-mitre-analytic--1fbe9da1-a760-4ac9-8ab0-59203a50fb82","name":"Analytic 0521","description":"Detects deletion or overwriting of bash history, syslog, audit logs, and .ssh metadata following privilege elevation or suspicious process spawning.","url":"https://attack.mitre.org/detectionstrategies/DET0184#AN0521","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"unlink, rename, open","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"auditd-syscall"},{"name":"linux:cli","channel":"cleared or truncated .bash_history","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-cli"}],"mutable_elements":[{"field":"MonitoredPaths","description":"Adjust based on syslog/auditd file paths (/var/log/messages, /var/log/audit/audit.log)"},{"field":"UserContext","description":"Scope to root/sudo usage or anomalous user behavior"}],"live":true,"detection_strategies":["DET0184"],"techniques":["T1070"]},{"id":"AN0522","stix_id":"x-mitre-analytic--2f0f5c7a-18ee-462e-b364-b1d8df3b2c02","name":"Analytic 0522","description":"Detects clearing of unified logs, deletion of plist files tied to persistence, and manipulation of Terminal history after initial execution.","url":"https://attack.mitre.org/detectionstrategies/DET0184#AN0522","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream cleared or truncated","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"unlink, fs_delete","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"fs-fsusage"},{"name":"macos:osquery","channel":"File modifications in ~/Library/Preferences/","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"PlistTargetPaths","description":"Define which plist paths relate to LaunchAgents or LaunchDaemons"},{"field":"ExecutionChainDepth","description":"Allow tuning for multi-process persistence chains"}],"live":true,"detection_strategies":["DET0184"],"techniques":["T1070"]},{"id":"AN0523","stix_id":"x-mitre-analytic--b3d533fc-010a-4ee8-b234-80f98e2443a0","name":"Analytic 0523","description":"Monitors tampering with audit logs, volumes, or mounted storage often used for side-channel logging (e.g., /var/log inside containers) post-compromise.","url":"https://attack.mitre.org/detectionstrategies/DET0184#AN0523","platforms":["Containers"],"log_source_references":[{"name":"docker:daemon","channel":"container file operations","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"docker-daemon"},{"name":"ebpf:syscalls","channel":"Unexpected container volume unmount + file deletion","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"ebpf-syscalls"}],"mutable_elements":[{"field":"LogMountPaths","description":"Tune based on how logs are exported (bind-mount, overlay)"},{"field":"ContainerLabelScope","description":"Limit detection to suspicious containers or runtime classes"}],"live":true,"detection_strategies":["DET0184"],"techniques":["T1070"]},{"id":"AN0524","stix_id":"x-mitre-analytic--f9b13a61-0110-4882-9384-3468d22ac221","name":"Analytic 0524","description":"Tracks suspicious use of ESXi shell commands or PowerCLI to delete logs, rotate system files, or tamper with hostd/vpxa history.","url":"https://attack.mitre.org/detectionstrategies/DET0184#AN0524","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"rm, clearlogs, logrotate","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"LogSourceType","description":"Tune per vCenter, vSphere, ESXi CLI telemetry collection"},{"field":"LogPathPattern","description":"Target specific high-value log paths (e.g., /var/log/hostd.log)"}],"live":true,"detection_strategies":["DET0184"],"techniques":["T1070"]},{"id":"AN0525","stix_id":"x-mitre-analytic--c15d6b5e-bbb7-4dc7-8b59-8ce2c0663c05","name":"Analytic 0525","description":"Detects deletion or hiding of security-related mail rules, audit mailboxes, or calendar/log sync artifacts indicative of tampering post-intrusion.","url":"https://attack.mitre.org/detectionstrategies/DET0184#AN0525","platforms":["Office Suite"],"log_source_references":[{"name":"m365:exchange","channel":"Remove-InboxRule, Clear-Mailbox","data_component":"DC0012","data_component_name":"Scheduled Job Modification","log_source_slug":"m365-exchange"},{"name":"m365:unified","channel":"PurgeAuditLogs, Remove-MailboxAuditLog","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"TargetMailboxScope","description":"Limit by VIP mailboxes or external-facing users"},{"field":"AuditLogDepth","description":"Tune for log deletion following lateral movement"}],"live":true,"detection_strategies":["DET0184"],"techniques":["T1070"]}],"live":true,"version":"1.0","techniques":["T1070"]}],"sigma_rules":[{"id":"0649be4a-aeb0-45b0-b89e-7f1668f6d9c0","title":"IIS WebServer Log Deletion via CommandLine Utilities","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-09-02","modified":null,"description":"Detects attempts to delete Internet Information Services (IIS) log files via command line utilities, which is a common defense evasion technique used by attackers to cover their tracks.\nThreat actors often abuse vulnerabilities in web applications hosted on IIS servers to gain initial access and later delete IIS logs to evade detection.\n","references":["https://learn.microsoft.com/en-us/iis/manage/provisioning-and-managing-iis/managing-iis-log-file-storage"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/process_creation/proc_creation_win_iis_logs_deletion.yml","techniques":["T1070"],"cves":[]},{"id":"07bdd2f5-9c58-4f38-aec8-e101bb79ef8d","title":"Terminal Server Client Connection History Cleared - Registry","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-10-19","modified":"2023-02-08","description":"Detects the deletion of registry keys containing the MSTSC connection history","references":["https://learn.microsoft.com/en-us/troubleshoot/windows-server/remote/remove-entries-from-remote-desktop-connection-computer","http://woshub.com/how-to-clear-rdp-connections-history/","https://www.trendmicro.com/en_us/research/23/a/vice-society-ransomware-group-targets-manufacturing-companies.html"],"logsource":{"product":"windows","category":"registry_delete"},"tags":["attack.persistence","attack.stealth","attack.defense-impairment","attack.t1070","attack.t1112"],"path":"rules/windows/registry/registry_delete/registry_delete_mstsc_history_cleared.yml","techniques":["T1070","T1112"],"cves":[]},{"id":"09570ae5-889e-43ea-aac0-0e1221fb3d95","title":"Remove Exported Mailbox from Exchange Webserver","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-08-27","modified":"2023-01-23","description":"Detects removal of an exported Exchange mailbox which could be to cover tracks from ProxyShell exploit","references":["https://github.com/rapid7/metasploit-framework/blob/1416b5776d963f21b7b5b45d19f3e961201e0aed/modules/exploits/windows/http/exchange_proxyshell_rce.rb#L430"],"logsource":{"product":"windows","service":"msexchange-management"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/builtin/msexchange/win_exchange_proxyshell_remove_mailbox_export.yml","techniques":["T1070"],"cves":[]},{"id":"115fdba9-f017-42e6-84cf-d5573bf2ddf8","title":"Disable of ETW Trace - Powershell","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-28","modified":"2022-11-25","description":"Detects usage of powershell cmdlets to disable or remove ETW trace sessions","references":["https://medium.com/palantir/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","car.2016-04-002"],"path":"rules/windows/powershell/powershell_script/posh_ps_etw_trace_evasion.yml","techniques":["T1070","T1685"],"cves":[]},{"id":"20f754db-d025-4a8f-9d74-e0037e999a9a","title":"SES Identity Has Been Deleted","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-12-13","modified":"2022-12-28","description":"Detects an instance of an SES identity being deleted via the \"DeleteIdentity\" event. This may be an indicator of an adversary removing the account that carried out suspicious or malicious activities","references":["https://unit42.paloaltonetworks.com/compromised-cloud-compute-credentials/"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.stealth","attack.t1070"],"path":"rules/cloud/aws/cloudtrail/aws_delete_identity.yml","techniques":["T1070"],"cves":[]},{"id":"270185ff-5f50-4d6d-a27f-24c3b8c9fef8","title":"Tomcat WebServer Logs Deleted","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-02-16","modified":null,"description":"Detects the deletion of tomcat WebServer logs which may indicate an attempt to destroy forensic evidence","references":["Internal Research","https://linuxhint.com/view-tomcat-logs-windows/"],"logsource":{"product":"windows","category":"file_delete"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/file/file_delete/file_delete_win_delete_tomcat_logs.yml","techniques":["T1070"],"cves":[]},{"id":"3132570d-cab2-4561-9ea6-1743644b2290","title":"Kubernetes Events Deleted","author":"Leo Tsaousis (@laripping)","status":"test","level":"medium","date":"2024-03-26","modified":null,"description":"Detects when events are deleted in Kubernetes.\nAn adversary may delete Kubernetes events in an attempt to evade detection.\n","references":["https://microsoft.github.io/Threat-Matrix-for-Kubernetes/techniques/Delete%20K8S%20events/"],"logsource":{"product":"kubernetes","category":"application","service":"audit"},"tags":["attack.stealth","attack.t1070"],"path":"rules/application/kubernetes/audit/kubernetes_audit_events_deleted.yml","techniques":["T1070"],"cves":[]},{"id":"3eb8c339-a765-48cc-a150-4364c04652bf","title":"IIS WebServer Access Logs Deleted","author":"Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-09-16","modified":"2023-02-15","description":"Detects the deletion of IIS WebServer access logs which may indicate an attempt to destroy forensic evidence","references":["https://www.elastic.co/guide/en/security/current/webserver-access-logs-deleted.html"],"logsource":{"product":"windows","category":"file_delete"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/file/file_delete/file_delete_win_delete_iis_access_logs.yml","techniques":["T1070"],"cves":[]},{"id":"4931188c-178e-4ee7-a348-39e8a7a56821","title":"Filter Driver Unloaded Via Fltmc.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-02-13","modified":"2025-10-07","description":"Detect filter driver unloading activity via fltmc.exe","references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","attack.t1685.001"],"path":"rules/windows/process_creation/proc_creation_win_fltmc_unload_driver.yml","techniques":["T1070","T1685","T1685.001"],"cves":[]},{"id":"4d7cda18-1b12-4e52-b45c-d28653210df8","title":"Sysmon Driver Unloaded Via Fltmc.EXE","author":"Kirill Kiryanov, oscd.community","status":"test","level":"high","date":"2019-10-23","modified":"2023-02-13","description":"Detects possible Sysmon filter driver unloaded via fltmc.exe","references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","attack.t1685.001"],"path":"rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml","techniques":["T1070","T1685","T1685.001"],"cves":[]},{"id":"63c779ba-f638-40a0-a593-ddd45e8b1ddc","title":"EventLog EVTX File Deleted","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-02-15","modified":null,"description":"Detects the deletion of the event log files which may indicate an attempt to destroy forensic evidence","references":["Internal Research"],"logsource":{"product":"windows","category":"file_delete"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/file/file_delete/file_delete_win_delete_event_log_files.yml","techniques":["T1070"],"cves":[]},{"id":"95d61234-7f56-465c-6f2d-b562c6fedbc4","title":"Linux Package Uninstall","author":"Tuan Le (NCSGroup), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2023-03-09","modified":null,"description":"Detects linux package removal using builtin tools such as \"yum\", \"apt\", \"apt-get\" or \"dpkg\".","references":["https://sysdig.com/blog/mitre-defense-evasion-falco","https://www.tutorialspoint.com/how-to-install-a-software-on-linux-using-yum-command","https://linuxhint.com/uninstall_yum_package/","https://linuxhint.com/uninstall-debian-packages/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.stealth","attack.t1070"],"path":"rules/linux/process_creation/proc_creation_lnx_remove_package.yml","techniques":["T1070"],"cves":[]},{"id":"9e9a9002-56c4-40fd-9eff-e4b09bfa5f6c","title":"DLL Load By System Process From Suspicious Locations","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-07-17","modified":"2023-09-18","description":"Detects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as \"C:\\Users\\Public\"","references":["https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC (Idea)"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/image_load/image_load_susp_dll_load_system_process.yml","techniques":["T1070"],"cves":[]},{"id":"a238b5d0-ce2d-4414-a676-7a531b3d13d6","title":"ETW Trace Evasion Activity","author":"@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community","status":"test","level":"high","date":"2019-03-22","modified":"2022-06-28","description":"Detects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.\n","references":["https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil","https://abuse.io/lockergoga.txt","https://medium.com/palantir/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","car.2016-04-002"],"path":"rules/windows/process_creation/proc_creation_win_susp_etw_trace_evasion.yml","techniques":["T1070","T1685"],"cves":[]},{"id":"a55349d8-9588-4c5a-8e3b-1925fe2a4ffe","title":"Exchange PowerShell Cmdlet History Deleted","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-10-26","modified":"2022-12-30","description":"Detects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence","references":["https://m365internals.com/2022/10/07/hunting-in-on-premises-exchange-server-logs/"],"logsource":{"product":"windows","category":"file_delete"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/file/file_delete/file_delete_win_delete_exchange_powershell_logs.yml","techniques":["T1070"],"cves":[]},{"id":"add64136-62e5-48ea-807e-88638d02df1e","title":"Fsutil Suspicious Invocation","author":"Ecco, E.M. Anhaus, oscd.community","status":"stable","level":"high","date":"2019-09-26","modified":"2023-09-09","description":"Detects suspicious parameters of fsutil (deleting USN journal, configuring it with small size, etc).\nMight be used by ransomwares during the attack (seen by NotPetya and others).\n","references":["https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070/T1070.md","https://eqllib.readthedocs.io/en/latest/analytics/c91f422a-5214-4b17-8664-c5fcf115c0a2.html","https://github.com/albertzsigovits/malware-notes/blob/558898932c1579ff589290092a2c8febefc3a4c9/Ransomware/Lockbit.md","https://blog.cluster25.duskrise.com/2023/05/22/back-in-black-blackbyte-nt"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.stealth","attack.t1070","attack.t1485"],"path":"rules/windows/process_creation/proc_creation_win_fsutil_usage.yml","techniques":["T1070","T1485"],"cves":[]},{"id":"bde47d4b-9987-405c-94c7-b080410e8ea7","title":"Clearing Windows Console History","author":"Austin Songer @austinsonger","status":"test","level":"high","date":"2021-11-25","modified":"2022-12-25","description":"Identifies when a user attempts to clear console history. An adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.","references":["https://stefanos.cloud/blog/kb/how-to-clear-the-powershell-command-history/","https://www.shellhacks.com/clear-history-powershell/","https://community.sophos.com/sophos-labs/b/blog/posts/powershell-command-history-forensics"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.stealth","attack.t1070","attack.t1070.003"],"path":"rules/windows/powershell/powershell_script/posh_ps_clearing_windows_console_history.yml","techniques":["T1070","T1070.003"],"cves":[]},{"id":"c947b146-0abc-4c87-9c64-b17e9d7274a2","title":"Shadow Copies Deletion Using Operating Systems Utilities","author":"Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)","status":"stable","level":"high","date":"2019-10-22","modified":"2022-11-03","description":"Shadow Copies deletion using operating systems utilities","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://blog.talosintelligence.com/2017/05/wannacry.html","https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/new-teslacrypt-ransomware-arrives-via-spam/","https://www.bleepingcomputer.com/news/security/why-everyone-should-disable-vssadmin-exe-now/","https://www.hybrid-analysis.com/sample/ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa?environmentId=100","https://github.com/Neo23x0/Raccine#the-process","https://github.com/Neo23x0/Raccine/blob/20a569fa21625086433dcce8bb2765d0ea08dcb6/yara/gen_ransomware_command_lines.yar","https://redcanary.com/blog/intelligence-insights-october-2021/","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackbyte-exbyte-ransomware"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.stealth","attack.t1070","attack.t1490"],"path":"rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml","techniques":["T1070","T1490"],"cves":[]},{"id":"c9fbe8e9-119d-40a6-9b59-dd58a5d84429","title":"Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE","author":"@neu5ron","status":"test","level":"medium","date":"2019-02-07","modified":"2023-02-15","description":"Detects potential malicious and unauthorized usage of bcdedit.exe","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/bcdedit--set","https://twitter.com/malwrhunterteam/status/1372536434125512712/photo/2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1070","attack.persistence","attack.t1542.003"],"path":"rules/windows/process_creation/proc_creation_win_bcdedit_susp_execution.yml","techniques":["T1070","T1542.003"],"cves":[]},{"id":"ff301988-c231-4bd0-834c-ac9d73b86586","title":"PowerShell Console History Logs Deleted","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-02-15","modified":null,"description":"Detects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence","references":["Internal Research"],"logsource":{"product":"windows","category":"file_delete"},"tags":["attack.stealth","attack.t1070"],"path":"rules/windows/file/file_delete/file_delete_win_delete_powershell_command_history.yml","techniques":["T1070"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-1389","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-41128","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-45382","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}