{
  "case": "2019-07-19",
  "captured_at": "2026-09-22T19:40:51.672Z",
  "url": "[local-instance]",
  "analysis_id": "961bdc9a-7460-440f-a246-f55748149bcc",
  "summary_id": "investigation-summary:60b13529-5cbc-4ec3-af47-296930292eeb",
  "model": "gpt-4.1-2025-04-14",
  "capture_sha256": "ae759973cbf42e9cd0db35a5450c99f6210fca2c22fb8e689d252e64211bfd36",
  "native_summary_saved": true,
  "source_sha256": "50557153d3c4b71e7db156a61ddd3c5ed8088d8b0da2fbb91b28a87c0a79209a",
  "screenshot_sha256": "90b9681d0e25fe7704d9076c140c677b1cf07119b4d3268b1dbaf892dbb56cec",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 985,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2019-07-19-traffic-analysis-exercise.pcap\n\nThe device with IP 172.16.4.205 made repeated outbound HTTP POST requests to 31.7.62.214 using a User-Agent string identifying NetSupport Manager remote-access software, over cleartext HTTP on TCP port 443.\n\nAround the same period, the same internal device sent large HTTP POST requests exceeding one megabyte each to 185.243.115.84 at b5689023.green.mattingsolutions.co, with POST traffic involving suspicious URL parameters.\n\nWho was involved\nInternal workstation Rotterdam-PC (IP 172.16.4.205) is associated with user matthijs.devries.\nKey indicators and why they matter\nThe IP 31.7.62.214 received repeated POST requests with a remote-access tool signature from 172.16.4.205.\nThe domain b5689023.green.mattingsolutions.co hosted large HTTP POST traffic, which may indicate suspicious outbound data transfer.\nSupported technique candidates\nOutbound HTTP POST requests to suspicious infrastructure are candidate Web Protocol C2 activity (T1071.001), not proven adversary command and control.\nWhat remains uncertain\nNo endpoint context or execution evidence confirms whether unauthorized remote access or exfiltration occurred; observable user behavior is unknown.\nNext check\nReview the endpoint Rotterdam-PC for remote-access software presence, user activity, and corroborating evidence of C2 or data exfiltration, as network traffic alone is insufficient for a full compromise assessment.\n\nModel: gpt-4.1-2025-04-14 · 164 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: ae759973cbf42e9cd0db35a5450c99f6210fca2c22fb8e689d252e64211bfd36\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.\n\n1 optional entry was omitted after validation; see the evidence details.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:50:20.372166+00:00",
    "image_sha256": "90b9681d0e25fe7704d9076c140c677b1cf07119b4d3268b1dbaf892dbb56cec",
    "notes": "Inspected full final card. Case filename and capture hash readable, no overlap or clipping. Badbundt is explicitly a withheld report, not an invented success. Semantic correctness is assessed separately.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
