{
  "case": "2018-08-12",
  "captured_at": "2026-09-22T19:41:14.780Z",
  "url": "[local-instance]",
  "analysis_id": "720a1250-ec20-4280-911f-2a97345018f1",
  "summary_id": "investigation-summary:faa2e9a4-9421-475e-b2aa-c3abee8088a2",
  "model": "gpt-4.1-2025-04-14",
  "capture_sha256": "c9e136e6e53daec4deec416e545d56e3c430dbc2d38374cf7a4dc839a0f4a3ff",
  "native_summary_saved": true,
  "source_sha256": "c1c81f5c3705058c5d48684db28dd73929550b4d42cce6a3826c60b75592837f",
  "screenshot_sha256": "725ea1f64ab59d7cf4ff461e08308757c9ae47de1d0475bb8f1628765e6fdfb9",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 1057,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2018-08-12-traffic-analysis-exercise.pcap\n\nThe internal host 192.168.1.95 (Petrov2018-PC) downloaded an HTTP file with SHA-256 b908d9b1001d0a39ba92501c086b1c25b05b171eeda035ae9f3e129d2776a314, which static review flagged as suspicious, but no execution is proven.\n\nFollowing these downloads, the same host established repeated HTTP POST connections to http://185.68.93.18/dot.php, consistent with automated beacon or callback patterns, but this activity alone does not prove compromise.\n\nWho was involved\n192.168.1.95 observed as the source of downloads and callbacks.\nPetrov2018-PC is the hostname of the involved device.\nmikhail.petrov account associated to 192.168.1.95 by Kerberos principal.\nKey indicators and why they matter\nSHA-256 b908d9b1001d0a39ba92501c086b1c25b05b171eeda035ae9f3e129d2776a314 is the downloaded suspicious file for review, flagged by static features.\nIP 185.68.93.18 is the external host receiving repeated HTTP POST callbacks from the involved host.\nhttp://185.68.93.18/dot.php is the suspicious callback URL for POST activity from the internal host.\nSupported technique candidates\nT1071.001 — Suspected use of application layer web protocols for command-and-control based on repeated HTTP POSTs to dot.php.\nT1105 — Possible ingress tool transfer via HTTP download, including suspicious script-like file, but adversary presence is not established by this alone.\nWhat remains uncertain\nIt is not established whether the suspicious downloaded file was executed or resulted in system compromise.\n\nModel: gpt-4.1-2025-04-14 · 169 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: c9e136e6e53daec4deec416e545d56e3c430dbc2d38374cf7a4dc839a0f4a3ff\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.\n\n1 optional entry was omitted after validation; see the evidence details.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:50:59.926094+00:00",
    "image_sha256": "725ea1f64ab59d7cf4ff461e08308757c9ae47de1d0475bb8f1628765e6fdfb9",
    "notes": "Individually viewed final card: narrative and labels legible, long hash wraps inside card, full provenance footer, no overlap or clipping. Content accuracy separately evaluated against publisher answers.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
