{
  "case": "2019-11-12",
  "captured_at": "2026-09-22T19:40:47.629Z",
  "url": "[local-instance]",
  "analysis_id": "76f521c2-4e4a-41d5-95ad-a44fd9887dd8",
  "summary_id": "investigation-summary:241f2780-d4c1-4048-8bdd-09d4fb6c15f8",
  "model": "gpt-4.1-2025-04-14",
  "capture_sha256": "1c607e6b1245a2ee781551fb8a9c629763f848410c3756f28d80615c55fc22d1",
  "native_summary_saved": true,
  "source_sha256": "11669be41dc356c75dfa8698a61cc334e24de51a01800d2a88f52d17bba0e9c3",
  "screenshot_sha256": "f136e71ad03bd0ca46293cfa35019f07f7bb521f9cab9c5b1c99c1ff56a7126f",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 862,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2019-11-12-traffic-analysis-exercise.pcap\n\nThe host 10.11.11.203 (TUCKER-WIN7-PC, candice.tucker) downloaded a file identified as a Windows executable (PE) from http://acjabogados.com/40group.tiff with SHA-256 8d5d36c8ffb0a9c81b145aa40c1ff3475702fb0b5f9e08e0577bdc405087e635.\n\nMultiple hosts in the environment, including TUCKER-WIN7-PC and others, retrieved various JavaScript files from reputable domains with no evidence in this data set of those scripts being malicious or executed beyond receiving them over HTTP.\n\nWho was involved\n10.11.11.203 is identified as TUCKER-WIN7-PC and user candice.tucker.\nUser candice.tucker is associated with 10.11.11.203 (TUCKER-WIN7-PC).\nTUCKER-WIN7-PC assigned to 10.11.11.203.\nWhat remains uncertain\nIt is not confirmed whether the downloaded PE file on TUCKER-WIN7-PC was executed or resulted in compromise, as the capture contains only the transfer and no endpoint activity.\nReputation and threat context for the downloaded executable are not fully established due to rate limiting or lack of matches in enrichment sources at the time of analysis.\nNext check\nFurther investigate the executable 8d5d36c8ffb0a9c81b145aa40c1ff3475702fb0b5f9e08e0577bdc405087e635 on TUCKER-WIN7-PC for signs of execution or persistent compromise.\n\nModel: gpt-4.1-2025-04-14 · 143 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: 1c607e6b1245a2ee781551fb8a9c629763f848410c3756f28d80615c55fc22d1\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.\n\n1 optional entry was omitted after validation; see the evidence details.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:50:20.162725+00:00",
    "image_sha256": "f136e71ad03bd0ca46293cfa35019f07f7bb521f9cab9c5b1c99c1ff56a7126f",
    "notes": "Inspected full final card. Case filename and capture hash readable, no overlap or clipping. Badbundt is explicitly a withheld report, not an invented success. Semantic correctness is assessed separately.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
