{
  "case": "2018-12-18",
  "captured_at": "2026-09-22T19:41:06.779Z",
  "url": "[local-instance]",
  "analysis_id": "0c443755-98f4-45dd-a9c4-e04e0415fe14",
  "summary_id": "investigation-summary:dc26ff68-c6d3-4f90-92b1-6c06d9cd5b6f",
  "model": "gpt-4.1-2025-04-14",
  "capture_sha256": "d35d186bb34fe0bf6a2e8787ebd71f44ec3ed0b90b3bbc890a97bad8823d92b8",
  "native_summary_saved": true,
  "source_sha256": "d034bec080cd2939a8c09a48ac49ee028af7fbf9fc06e1b3074bba7949d64846",
  "screenshot_sha256": "58b6de10f27ff256ca6e62c80b913e5c13823fb76ea1e2434d722a0aac2ebe97",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 817,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2018-12-18-traffic-analysis-exercise.pcap\n\nHost 172.16.3.133 downloaded a Portable Executable (PE) file from 93.90.146.108 via http://www.prolightphotovideo.net/dVk_hwBIaehh/, indicating potential delivery of an executable payload.\n\nHost 172.16.3.133 also downloaded an OLE document from 82.80.25.215 at http://entisrael.com/wp-content/uploads/2018/jemHu-SahjLpTw_r-7Kd/PaymentStatus/default/US_us/Companies-Invoice-0970945/, which may contain a malicious macro or embedded exploit.\n\nNo evidence confirms execution of the downloaded files or subsequent compromise within the available capture.\n\nWho was involved\n172.16.3.133 appears as the client for both high-risk file downloads and is associated with the account conception.varner.\nAccount conception.varner is bound to 172.16.3.133 via Kerberos principal activity.\nWhat remains uncertain\nIt remains unknown if the downloaded PE or OLE files were executed or if any further post-compromise activity occurred in this session.\nNext check\nReview endpoint logs on 172.16.3.133 for signs of execution or process launch correlated with the SHA-256 values of the downloaded PE and OLE files.\n\nModel: gpt-4.1-2025-04-14 · 127 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: d35d186bb34fe0bf6a2e8787ebd71f44ec3ed0b90b3bbc890a97bad8823d92b8\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.\n\n2 optional entries were omitted after validation; see the evidence details.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:50:47.603314+00:00",
    "image_sha256": "58b6de10f27ff256ca6e62c80b913e5c13823fb76ea1e2434d722a0aac2ebe97",
    "notes": "Final card inspected visually: complete frame, readable text, case filename and hash consistent, no startup banner. Failed cases explicitly show withheld status without invented narrative.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
