Give me a hint

Hello, My name is Bob and i am new here. I am learnig to work with wireshark myself and trying to improve myself. A cybercrimeteam send me a pcapng file and asked me this. Quote: we intercept traffic in a ransomware case. Can you find out if the ransomware was sent? I have the ip adres and email adres from the ransomguy. It was sent thru SMTP How can i see if the ransome software was sent with the found mail? I Hope someone can help me.

