PCAP investigation summary

What happened

The device with IP 139.199.184.166 initiated multiple repeated HTTP POST requests to the URLs http://128.199.64.235/1.php and http://128.199.64.235/qq.php, which may indicate beaconing or suspicious data transfer activity.

Reputation and threat intelligence checks on 139.199.184.166 and the contacted URLs returned no confirmation of known threats, but rate limiting or the absence of records does not mean the endpoints are benign.

Who was involved

Key indicators

What remains uncertain

Analyst-review draft. Exact evidence references and provider provenance are retained in the structured record.