PCAP investigation summary

What happened

The host at 10.3.11.194 downloaded three files with PE (Windows executable) content from http://64.44.133.131/images/cursor.png and http://64.44.133.131/images/imgpaper.png during the capture window; these files were served with non-executable URL extensions, which is suspicious but does not prove execution or compromise.

Who was involved

Key indicators

What remains uncertain

Next check

Analyst-review draft. Exact evidence references and provider provenance are retained in the structured record.