PCAP investigation summary

What happened

The host Ferguson-Win-PC at IP 10.2.23.231 downloaded four different PE files from external servers using HTTP requests, with three files served under PNG or JPG extensions, which is inconsistent with their content type and is suspicious.

A PE file named 'troll1.jpg' was also downloaded from 209.141.55.226 by the same host Ferguson-Win-PC at 10.2.23.231, further supporting suspicious transfer activity.

Who was involved

What remains uncertain

Next check

Analyst-review draft. Exact evidence references and provider provenance are retained in the structured record.