diff --git a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.json b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.json index d154716..8de76b0 100644 --- a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.json +++ b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.json @@ -226,8 +226,8 @@ "x-action--9428a7c0-aee8-4b30-af0a-61d2625d8346", "x-action--671cb16d-69b9-4184-89cb-a208db198810" ], - "reconstructed_from": "x-crime-case--a6ee60b6-9460-4800-ae6f-cf1cb8cd34fe", - "reconstructed_by": "x-investigator--096e9478-2b7b-5bc9-a035-08464b16fc7b", + "reconstructed_from_ref": "x-crime-case--a6ee60b6-9460-4800-ae6f-cf1cb8cd34fe", + "reconstructed_by_ref": "x-investigator--096e9478-2b7b-5bc9-a035-08464b16fc7b", "created_by_ref": "identity--4f922f49-b4ac-41d6-b701-b374d7dc9b22", "created": "2021-02-16T11:26:00Z", "modified": "2021-02-19T18:27:00Z" @@ -255,7 +255,7 @@ "id": "indicator--e7a4aa2b-dfbe-4cf4-be2e-b5811699264d", "name": "delete indicator", "description": "Indication of delete", - "pattern": "[file:hashes.MD5='ca03f2eed3db06a82a8a31b3a3defa24' or file:hashes.MD5='ed870202082ea4fd8f5488533a561b35' or file:hashes.MD5='76610b7bdb85e5f65e96df3f7e417a74' or file:hashes.MD5='d03dc23d4ec39e4d16da3c46d2932d62']", + "pattern": "[file:extensions:status='recovered' and file:extensions:content_tags[0]='rhino']", "pattern_type": "stix", "created_by_ref": "identity--4f922f49-b4ac-41d6-b701-b374d7dc9b22", "created": "2021-02-15T12:15:00Z", @@ -270,7 +270,10 @@ "MD5": "ca03f2eed3db06a82a8a31b3a3defa24" }, "extensions": { - "recovered_file_name": "f0106393.jpg" + "description": "recovered from deletion", + "status": "recovered", + "content_tags": ["rhino"], + "file_name": "f0106393.jpg" } }, { @@ -282,7 +285,10 @@ "MD5": "ed870202082ea4fd8f5488533a561b35" }, "extensions": { - "recovered_file_name": "f0106409.jpg" + "description": "recovered from deletion", + "status": "recovered", + "content_tags": ["rhino"], + "file_name": "f0106409.jpg" } }, { @@ -294,7 +300,10 @@ "MD5": "76610b7bdb85e5f65e96df3f7e417a74" }, "extensions": { - "recovered_file_name": "f0106865.gif" + "description": "recovered from deletion", + "status": "recovered", + "content_tags": ["rhino"], + "file_name": "f0106865.gif" } }, { @@ -306,7 +315,10 @@ "MD5": "d03dc23d4ec39e4d16da3c46d2932d62" }, "extensions": { - "recovered_file_name": "f0106889.gif" + "description": "recovered from deletion", + "status": "recovered", + "content_tags": ["rhino"], + "file_name": "f0106889.gif" } }, { @@ -392,7 +404,9 @@ }, "content_ref": "artifact--899e1d63-20ae-5487-b684-df8019d4177c", "extensions": { - "recovered_file_name": "f0335017_She_died_in_February_at_the_age_of_74.doc" + "description": "recovered from deletion", + "status": "recovered", + "file_name": "f0335017_She_died_in_February_at_the_age_of_74.doc" } }, { @@ -412,7 +426,7 @@ "id": "indicator--afb0a853-e4c7-45a8-afea-d9f7c2dac3c1", "name": "delete doc indicator", "description": "Indication of delete a doc file that is recovered from the USB", - "pattern": "[artifact:payload_bin MATCHES 'I “hid” the photos']", + "pattern": "[file:extensions:status='recovered']", "pattern_type": "stix", "created_by_ref": "identity--4f922f49-b4ac-41d6-b701-b374d7dc9b22", "created": "2021-02-15T12:15:00Z", @@ -481,7 +495,9 @@ "MD5": "6bd0e9bd4fb4a738f9ca4c351a853281" }, "extensions": { - "recovered_file_name": "f0105065.jpg" + "description": "recovered from deletion", + "status": "recovered", + "file_name": "f0105065.jpg" } }, { @@ -497,7 +513,7 @@ "id": "indicator--e9d899b9-0c56-4108-839f-9cef41e37b34", "name": "use a steganography tool indicator", "description": "Indication of using steganography tool", - "pattern": "[artifact:payload_bin MATCHES 'jphide' and (file:hashes.'MD5'='63a39823f80b321c2dcd112158b55011' or file:hashes.'MD5'='87018ef0cfdb91e818d92efeb9c19338')]", + "pattern": "[artifact:payload_bin MATCHES 'anBoaWRl' and file:extensions:status='decoded' and exists artifact--01b778f5-e334-52a5-a49d-f9b2de330be9 and exists artifact--5bb67aa9-d849-465d-a433-114063836965]", "pattern_type": "stix", "created_by_ref": "identity--4f922f49-b4ac-41d6-b701-b374d7dc9b22", "created": "2021-02-17T15:41:00Z", @@ -510,9 +526,11 @@ "labels": ["hide", "password", "image"], "number_observed": 1, "object_refs": [ + "file--10571ebd-b587-50a6-9e86-acb3cba78437", "artifact--a0c90013-2008-57bc-b58e-88ed2e81a479", "artifact--01b778f5-e334-52a5-a49d-f9b2de330be9", "file--35ef592a-98bc-564e-81ce-d269cdbf8a1d", + "file--04c87cba-c468-59e0-8e26-e4652344489f", "artifact--9d44c6b5-e425-4499-a9e3-b569304f32b1", "artifact--5bb67aa9-d849-465d-a433-114063836965", "file--35ef592a-98bc-564e-81ce-d269cdbf8a1d" @@ -573,7 +591,10 @@ "MD5": "63a39823f80b321c2dcd112158b55011" }, "extensions": { - "recovered_file_name": "r065.jpg" + "description": "decoded by stegdetect", + "status": "decoded", + "content_tags": ["rhino"], + "file_name": "r065.jpg" } }, { @@ -606,7 +627,9 @@ "MD5": "4d37a1033450b8cc96ffd1564829d321" }, "extensions": { - "recovered_file_name": "f0104249.jpg" + "description": "recovered from deletion", + "status": "recovered", + "file_name": "f0104249.jpg" } }, { @@ -653,7 +676,10 @@ "MD5": "87018ef0cfdb91e818d92efeb9c19338" }, "extensions": { - "recovered_file_name": "r249.jpg" + "description": "decoded by stegdetect", + "status": "decoded", + "content_tags": ["rhino"], + "file_name": "r249.jpg" } }, { diff --git a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.svg b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.svg new file mode 100644 index 0000000..916a160 --- /dev/null +++ b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.svg @@ -0,0 +1,1754 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Page-1 + + + + Sheet.1 + identity: Frank Xu + + + + identity: Frank Xu + + Sheet.2 + identity: administrator + + + + identity: administrator + + Rectangle.1067 + x-investigator: Frank Xu + + + + + + + x-investigator:Frank Xu + + Dynamic connector.1001 + attributed-to + + + + + attributed-to + + Rectangle.1002 + x-crime-case: Illegal Rhino Images Possession + + + + + + + x-crime-case:Illegal Rhino Images Possession + + Sheet.1003 + file: Rhino Hunt.pdf + + + + file: Rhino Hunt.pdf + + Sheet.1004 + file: rhino.log + + + + file: rhino.log + + Sheet.1005 + file: rhino2.log + + + + file: rhino2.log + + Sheet.1006 + file: rhino3.log + + + + file: rhino3.log + + Dynamic connector.1007 + case_file_refs + + + + + case_file_refs + + Dynamic connector.1008 + case_file_refs + + + + + case_file_refs + + Dynamic connector.1009 + case_file_refs + + + + + case_file_refs + + Dynamic connector.1010 + case_file_refs + + + + + case_file_refs + + Rectangle.1011 + x-image: rhino usb image + + + + + + + x-image:rhino usb image + + Dynamic connector.1012 + investigates + + + + + investigates + + Rectangle.1014 + x-investigator: administrator + + + + + + + x-investigator:administrator + + Dynamic connector.1015 + attributed-to + + + + + attributed-to + + Dynamic connector.1016 + captures-evidence-in + + + + + captures-evidence-in + + Dynamic connector.1017 + captures-evidence-in + + + + + captures-evidence-in + + Dynamic connector.1018 + captures-evidence-in + + + + + captures-evidence-in + + Dynamic connector.1019 + acquired_by_ref + + + + + acquired_by_ref + + Dynamic connector.1020 + evidence-of + + + + + evidence-of + + Rectangle.1021 + x-action: Delete Images + + + + + + + x-action:Delete Images + + Rectangle.4 + x-secondary-storage-: USB + + + + + + + x-secondary-storage-:USB + + Dynamic connector.1023 + image-of + + + + + image-of + + Dynamic connector.1024 + action_refs + + + + + action_refs + + Rectangle.1001 + indicator: Delete images indicator + + + + + + + indicator:Delete images indicator + + Rectangle.1027 + observed-data: Deleted images + + + + + + + observed-data:Deleted images + + Dynamic connector.1028 + indicated-by + + + + + indicated-by + + Rectangle.1006 + x-timeline + + + + + + + x-timeline + + Dynamic connector.1031 + reconstructed_by_ref + + + + + reconstructed_by_ref + + Dynamic connector.1032 + based-on + + + + + based-on + + Rectangle.1075 + file: f0106393.jpg + + + + + + + file:f0106393.jpg + + Dynamic connector.1035 + object_refs + + + + + object_refs + + Rectangle.1098 + x-investigation-tool: PhotoRec7.1 + + + + + + + x-investigation-tool:PhotoRec7.1 + + Rectangle.1039 + file: f0106409.jpg + + + + + + + file:f0106409.jpg + + Dynamic connector.1043 + object_refs + + + + + object_refs + + Rectangle.1044 + file: f0106865.gif" + + + + + + + file:f0106865.gif" + + Dynamic connector.1047 + object_refs + + + + + object_refs + + Rectangle.1049 + file: f0106889.gif + + + + + + + file:f0106889.gif + + Dynamic connector.1051 + object_refs + + + + + object_refs + + Sheet.1054 + artifact: I “hid” the photos + + + + artifact:I “hid” the photos + + Rectangle.1055 + file: F0335017.doc + + + + + + + file:F0335017.doc + + Dynamic connector.1056 + content_ref + + + + + content_ref + + Rectangle.1059 + observed-data: Deleted doc + + + + + + + observed-data:Deleted doc + + Dynamic connector.1060 + object_refs + + + + + object_refs + + Rectangle.1061 + Indicator: Delete doc indicator + + + + + + + Indicator:Delete doc indicator + + Dynamic connector.1062 + based-on + + + + + based-on + + Rectangle.1063 + x-action: Delete .doc + + + + + + + x-action:Delete .doc + + Dynamic connector.1064 + action_refs + + + + + action_refs + + Dynamic connector.1065 + indicated-by + + + + + indicated-by + + Rectangle.1067 + file: F0105065.jpg + + + + + + + file:F0105065.jpg + + Rectangle.1068 + Indicator: steganographic tool, images indicator + + + + + + + Indicator:steganographic tool, images indicator + + Rectangle.1069 + artifact: jphide + + + + + + + artifact:jphide + + Rectangle.1070 + x-investigation-tool: stegdetect + + + + + + + x-investigation-tool:stegdetect + + Dynamic connector.1071 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1072 + outputs_refs + + + + + outputs_refs + + Rectangle.1073 + observed-data: steg tool and images + + + + + + + observed-data:steg tool and images + + Dynamic connector.1074 + object_refs + + + + + object_refs + + Dynamic connector.1075 + based-on + + + + + based-on + + Dynamic connector.1076 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1077 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1078 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1079 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1080 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1081 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1082 + imputs_refs + + + + + imputs_refs + + Rectangle.1083 + x-action: Hide Images + + + + + + + x-action:Hide Images + + Dynamic connector.1084 + targets_refs + + + + + targets_refs + + Dynamic connector.1085 + targets_refs + + + + + targets_refs + + Dynamic connector.1086 + targets_refs + + + + + targets_refs + + Dynamic connector.1087 + indicated-by + + + + + indicated-by + + Dynamic connector.1088 + action_refs + + + + + action_refs + + Sheet.1089 + artifact: password-gator + + + + artifact:password-gator + + Dynamic connector.1090 + outputs_refs + + + + + outputs_refs + + Rectangle.1091 + x-investigation-tool: jpseek + + + + + + + x-investigation-tool:jpseek + + Dynamic connector.1092 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1093 + inputs_refs + + + + + inputs_refs + + Rectangle.1094 + file: r065.jpg + + + + + + + file:r065.jpg + + Dynamic connector.1095 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1096 + object_refs + + + + + object_refs + + Dynamic connector.1097 + object_refs + + + + + object_refs + + Rectangle.1098 + file: F0104249.jpg + + + + + + + file:F0104249.jpg + + Dynamic connector.1099 + outputs_refs + + + + + outputs_refs + + Rectangle.1100 + artifact: jphide + + + + + + + artifact:jphide + + Sheet.1101 + artifact: password-gumbo + + + + artifact:password-gumbo + + Rectangle.1102 + x-investigation-tool: stegdetect + + + + + + + x-investigation-tool:stegdetect + + Dynamic connector.1103 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1104 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1105 + outputs_refs + + + + + outputs_refs + + Rectangle.1106 + file: r249.jpg + + + + + + + file:r249.jpg + + Rectangle.1107 + x-investigation-tool: jpseek + + + + + + + x-investigation-tool:jpseek + + Dynamic connector.1108 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1109 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1110 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1111 + object_refs + + + + + object_refs + + Dynamic connector.1112 + object_refs + + + + + object_refs + + Dynamic connector.1113 + object_refs + + + + + object_refs + + Rectangle.1114 + url: 137.30.120.40 + + + + + + + url:137.30.120.40 + + Rectangle.1115 + url: 137.30.122.253 + + + + + + + url:137.30.122.253 + + Rectangle.1116 + file: rhino1.jpg + + + + + + + file:rhino1.jpg + + Rectangle.1117 + network-traffic: rhino1.jpg + + + + + + + network-traffic:rhino1.jpg + + Dynamic connector.1118 + src_ref + + + + + src_ref + + Dynamic connector.1119 + dst_ref + + + + + dst_ref + + Rectangle.1120 + x-investigation-tool: Wireshark + + + + + + + x-investigation-tool:Wireshark + + Dynamic connector.1121 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1122 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1123 + outputs_refs + + + + + outputs_refs + + Rectangle.1124 + observed-data: network images FTP + + + + + + + observed-data:network images FTP + + Dynamic connector.1125 + object_refs + + + + + object_refs + + Dynamic connector.1126 + object_refs + + + + + object_refs + + Rectangle.1127 + indicator: upload indicator + + + + + + + indicator:upload indicator + + Dynamic connector.1128 + based-on + + + + + based-on + + Rectangle.1129 + x-action: upload Images + + + + + + + x-action:upload Images + + Dynamic connector.1130 + targets_refs + + + + + targets_refs + + Dynamic connector.1131 + indicated-by + + + + + indicated-by + + Dynamic connector.1132 + action_refs + + + + + action_refs + + Rectangle.1133 + network-traffic: rhino3.jpg + + + + + + + network-traffic:rhino3.jpg + + Dynamic connector.1134 + des_ref + + + + + des_ref + + Dynamic connector.1135 + src_ref + + + + + src_ref + + Rectangle.1137 + file: rhino3.jpg + + + + + + + file:rhino3.jpg + + Dynamic connector.1138 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1139 + object_refs + + + + + object_refs + + Dynamic connector.1140 + object_refs + + + + + object_refs + + Rectangle.1141 + network-traffic: contraband.zip + + + + + + + network-traffic:contraband.zip + + Dynamic connector.1142 + outputs_refs + + + + + outputs_refs + + Rectangle.1143 + file: contraband.zip + + + + + + + file:contraband.zip + + Rectangle.1144 + file: rhino2.jpg + + + + + + + file:rhino2.jpg + + Sheet.1145 + artifact: password.monkey + + + + artifact:password.monkey + + Rectangle.1146 + x-investigation-tool: fcrackzip + + + + + + + x-investigation-tool:fcrackzip + + Dynamic connector.1147 + inputs_ref + + + + + inputs_ref + + Dynamic connector.1148 + outputs_ref + + + + + outputs_ref + + Dynamic connector.1149 + extensions.archive-ext.contains_refs + + + + + extensions.archive-ext.contains_refs + + Dynamic connector.1150 + extensions.archive-ext.contains_refs + + + + + extensions.archive-ext.contains_refs + + Dynamic connector.1151 + src_ref + + + + + src_ref + + Dynamic connector.1152 + des_ref + + + + + des_ref + + Dynamic connector.1153 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1154 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1155 + + + + Dynamic connector.1156 + object_refs + + + + + object_refs + + Dynamic connector.1157 + object_refs + + + + + object_refs + + Dynamic connector.1158 + outputs_refs + + + + + outputs_refs + + Rectangle.1159 + url: 137.30.123.234 + + + + + + + url:137.30.123.234 + + Rectangle.1160 + url: 137.30.120.37 + + + + + + + url:137.30.120.37 + + Rectangle.1161 + network-traffic: rhino4.jpg + + + + + + + network-traffic:rhino4.jpg + + Rectangle.1162 + file: rhino4.jpg + + + + + + + file:rhino4.jpg + + Dynamic connector.1163 + src_ref + + + + + src_ref + + Dynamic connector.1164 + dst_ref + + + + + dst_ref + + Rectangle.1165 + x-investigation-tool: Wireshark + + + + + + + x-investigation-tool:Wireshark + + Dynamic connector.1166 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1167 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1168 + outputs_refs + + + + + outputs_refs + + Rectangle.1169 + observed-data: http download images + + + + + + + observed-data:http download images + + Dynamic connector.1170 + object_refs + + + + + object_refs + + Dynamic connector.1171 + object_refs + + + + + object_refs + + Rectangle.1172 + Indicator: download image pattern + + + + + + + Indicator:download image pattern + + Dynamic connector.1173 + based-on + + + + + based-on + + Dynamic connector.1174 + targets_refs + + + + + targets_refs + + Dynamic connector.1175 + targets_refs + + + + + targets_refs + + Dynamic connector.1176 + targets_refs + + + + + targets_refs + + Dynamic connector.1177 + targets_refs + + + + + targets_refs + + Dynamic connector.1178 + targets_refs + + + + + targets_refs + + Rectangle.1179 + x-action: Download Images + + + + + + + x-action:Download Images + + Dynamic connector.1180 + action_refs + + + + + action_refs + + Dynamic connector.1181 + indicated-by + + + + + indicated-by + + Rectangle.1182 + network-traffic: rhino5.gif + + + + + + + network-traffic:rhino5.gif + + Dynamic connector.1183 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1184 + src_ref + + + + + src_ref + + Dynamic connector.1185 + det_ref + + + + + det_ref + + Rectangle.1186 + file: rhino5.gif + + + + + + + file:rhino5.gif + + Dynamic connector.1187 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1188 + object_refs + + + + + object_refs + + Dynamic connector.1189 + object_refs + + + + + object_refs + + Dynamic connector.1190 + targets_refs + + + + + targets_refs + + Dynamic connector.1191 + targets_refs + + + + + targets_refs + + Dynamic connector.1192 + reconstructed_from_ref + + + + + reconstructed_from_ref + + Dynamic connector.1197 + object_refs + + + + + object_refs + + Dynamic connector.1198 + object_refs + + + + + object_refs + + + + + + + + + + + + + + + + + Note.1193 + [file:extensions:status='recovered' and file:extensions:conte... + + + + + + + [file:extensions:status='recovered' and file:extensions:content_tags[0]='rhino'] + + Sheet.1194 + + + + + + + + + + + + + + + + + + + + + + + Note.1195 + //"jphide tool used for hidding images"+"two passwords found"... + + + + + + + //"jphide tool used for hidding images"+"two passwords found" + "two jpgs are decoded from other images"[artifact:payload_bin MATCHES 'anBoaWRl' and file:extensions:status='decoded' and exists artifact--01b778f5-e334-52a5-a49d-f9b2de330be9 and exists artifact--5bb67aa9-d849-465d-a433-114063836965] + + Sheet.1196 + + + + + + + + diff --git a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx index 4313942..84e7529 100644 Binary files a/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx and b/STIX_for_digital_forensics/Illegal_Possession_Images/illegal_possession_image.vsdx differ diff --git a/STIX_for_digital_forensics/readme.md b/STIX_for_digital_forensics/readme.md index bdf1b71..b3330dd 100644 --- a/STIX_for_digital_forensics/readme.md +++ b/STIX_for_digital_forensics/readme.md @@ -416,14 +416,14 @@ A Timeline object describes a specific cybercrime case that is represented by a ## Timeline Specific Properties -| Property Name | Type | Description | -| ------------------ | --------------------- | ---------------------------------------------------------------------- | -| type (required) | string | The value of this property MUST be x-timeline. | -| action_refs | list of type x-action | Specifies a list of actions in chronological order. | -| name | string | Specifies the name of a timeline. | -| description | string | A description that provides more details and context about a timeline. | -| reconstructed_from | identifier | Specifies timeline is reconstructed from a crime case. | -| reconstructed_by | identifier | Specifies timeline is reconstructed by an investigator. | +| Property Name | Type | Description | +| ---------------------- | --------------------- | ---------------------------------------------------------------------- | +| type (required) | string | The value of this property MUST be x-timeline. | +| action_refs | list of type x-action | Specifies a list of actions in chronological order. | +| name | string | Specifies the name of a timeline. | +| description | string | A description that provides more details and context about a timeline. | +| reconstructed_from_ref | identifier | Specifies timeline is reconstructed from a crime case. | +| reconstructed_by_ref | identifier | Specifies timeline is reconstructed by an investigator. | ### Relationships @@ -445,7 +445,7 @@ A Timeline object describes a specific cybercrime case that is represented by a "x-action--6ba0fce7-1ff9-44a4-9fbb-28760afc7827", "x-action--83aee86d-1523-4111-938e-8edc8a6c804f" ], - "reconstructed_from": "x-crime-case--49aadd9f-8bb0-4728-bd56-7bc708714516", + "reconstructed_from_ref": "x-crime-case--49aadd9f-8bb0-4728-bd56-7bc708714516", "exploits": "user-account-2485b844-4efe-4343-84c8-eb33312dd56f", "created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff", "created": "2021-04-06T20:03:00.000Z",