PCAP investigation summary

What happened

The device with IP 172.16.4.205 made repeated outbound HTTP POST requests to 31.7.62.214 using a User-Agent string identifying NetSupport Manager remote-access software, over cleartext HTTP on TCP port 443.

Around the same period, the same internal device sent large HTTP POST requests exceeding one megabyte each to 185.243.115.84 at b5689023.green.mattingsolutions.co, with POST traffic involving suspicious URL parameters.

Who was involved

Key indicators

Supported technique candidates

What remains uncertain

Next check

Analyst-review draft. Exact evidence references and provider provenance are retained in the structured record.