{
  "case": "2020-01-30",
  "captured_at": "2026-09-22T19:40:41.448Z",
  "url": "[local-instance]",
  "analysis_id": "05851801-c224-489b-b9da-9e5d035c60b4",
  "summary_id": "investigation-summary:28fb5145-e166-4b00-abc3-e4b1ea541095",
  "model": "claude-opus-4-8",
  "capture_sha256": "51c84227023072a05ed3b4cae03662c7df80780551b6119c8af97301472642d4",
  "native_summary_saved": true,
  "source_sha256": "09bae3f06c5a400dfa5ada4377e471399b4f684617bec6fba6133bcb5abfec3f",
  "screenshot_sha256": "e77d26d458a1ebe3b30410f9b4f90313e5d47b26f9b71f94a10f64b52f91481d",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 897,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2020-01-30-traffic-analysis-exercise.pcap\n\nWindows host 10.20.30.227 (DESKTOP-4C02EMG, Kerberos principal alejandrina.hogue) downloaded a PE executable over cleartext HTTP from http://gengrasjeepram.com/sv.exe (server 49.51.133.162).\n\nThe same host sent repeated HTTP POST requests to twereptale.com (81.177.6.156) at /4/forum.php and /mlu/forum.php with unusual user-agent strings, a pattern suitable for beaconing review.\n\nNo packet evidence establishes execution of the downloaded PE or any successful exfiltration; endpoint payloads were not decrypted and no actor attribution is supported.\n\nWho was involved\n10.20.30.227 is the internal host that downloaded the PE and generated the suspicious POST traffic.\nKerberos client principal alejandrina.hogue is bound to host 10.20.30.227.\nWhat remains uncertain\nWhether the downloaded PE executed or established persistence is unestablished; encrypted payloads were not decrypted and no endpoint execution was observed.\nReputation of the download and POST destinations is inconclusive: VirusTotal was rate-limited and ThreatFox/MalwareBazaar returned not_found or not-applicable, which does not mean clean.\nNext check\nSubmit the recovered PE (SHA-256 995cbbb422634d497d65e12454cd5832cf1b4422189d9ec06efa88ed56891cda) for sandbox detonation and reputation lookup to determine maliciousness.\n\nModel: claude-opus-4-8 · 150 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: 51c84227023072a05ed3b4cae03662c7df80780551b6119c8af97301472642d4\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.\n\n4 optional entries were omitted after validation; see the evidence details.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:50:08.979742+00:00",
    "image_sha256": "e77d26d458a1ebe3b30410f9b4f90313e5d47b26f9b71f94a10f64b52f91481d",
    "notes": "Viewed final 1100px native report: complete readable narrative, consistent case filename, visible model and capture hash, no clipped text or overlay. Semantic failures evaluated separately.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
