Hello all,

According to the Wireshark record my computer connects to various services often, including Amazon, Hetzner, 1337 Services GmbH, Evanzo GmbH and ThomasFamilyInvestments. The most often were the connections to mail.my-mail.rocks which is a part of Netcup GmbH. I have a somewhat minimal distro and the attached recordings were made when no app was open including no browser. I can send the other screenshots showing other connections too. I’m suspecting of malware since some time ago but can you help me clarify these connections please?

  • infjarchninja@lemmy.ml
    link
    fedilink
    arrow-up
    19
    ·
    9 days ago

    I find wireshark too confusing unless you have a lot of experience with it.

    It looks like you are using linux because I see Wlan0 at the top of the image

    I use ss

    ss --help

    to see what you are connecting to

    ss -x -a

    ss -o state established

    ss -o state established ‘( dport = :http or sport = :http )’

    what processes are using open sockets

    ss -pl

    TCP sockets

    ss -t -a

    UDP sockets

    ss -t -a

    a deeper guide here:

    https://www.cyberciti.biz/tips/linux-investigate-sockets-network-connections.html

  • anon5621@lemmy.ml
    link
    fedilink
    arrow-up
    16
    ·
    9 days ago

    Just open sudo ss -tulpn u will see all programs with opened port and u will killing disabling until u will find source of network noise

      • Clark@lemmy.mlOP
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        9 days ago

        i only have these over long term but brave was closed when recording:

        Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
        udp ESTAB 0 0 192.168.1.100%wlan0:68 192.168.1.1:67 users:((“NetworkManager”,pid=1065,fd=27))
        tcp ESTAB 0 0 192.168.1.100:57728 185.246.86.175:9001 users:((“tor”,pid=1143,fd=16))
        tcp ESTAB 0 0 192.168.1.100:60406 54.36.178.108:443 users:((“brave”,pid=5153,fd=27))
        tcp ESTAB 0 0 192.168.1.100:40606 89.58.56.112:587 users:((“tor”,pid=1143,fd=12))

        • nitrolife@rekabu.ru
          link
          fedilink
          arrow-up
          9
          ·
          edit-2
          9 days ago

          If you are receiving data from tor, then you are most likely seeing these connections. They also change over time, so tor relay nodes change and can be located anywhere.

          In addition, in the example you have port 9001, which means that relaying is most likely enabled in your client and you are a relay for other participants. Check the settings of the tor (relay/bridge).

            • Clark@lemmy.mlOP
              link
              fedilink
              arrow-up
              1
              ·
              9 days ago

              No, it wasn’t at the time of recording. It was a confirmation later on that tor and network manager were the only apps using the ports with brave opened.

    • Clark@lemmy.mlOP
      link
      fedilink
      arrow-up
      3
      ·
      9 days ago

      so am i running a relay in the background although tor browser is closed?

      • habitualTartare@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        9 days ago

        If it’s like a vpn interface, it’s still running as a deamon in the background even if the browsers are closed.

        Like others have said you can check what application is using each open port. You can also check running processes (ps | grep keywords) and interfaces (ip a).

  • stupid_asshole69 [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    5
    ·
    9 days ago

    That screenshot just looks like a computer (.100, is that you?) dialing the upstream device (a zyxel!), it doesn’t seem to show what the intended recipient is. If you’re running windows then the start menu ads do crazy stuff. Also I asked if that last local ip octet is you because wireshark will show you other computers traffic coming across its wireless interface.

    From a high port to a low port makes me think it’s someone else on your network doing piracy.

    • Clark@lemmy.mlOP
      link
      fedilink
      arrow-up
      3
      ·
      9 days ago

      Yes, .100 is me. I have a Zyxel router, should it show the intended recipient? I’m running Linux. What do you mean by a high port to a low port? I also think there is a malware.

      • stupid_asshole69 [none/use name]@hexbear.net
        link
        fedilink
        English
        arrow-up
        3
        ·
        9 days ago

        If you think there’s malware then just wipe and reinstall.

        If you wanna find out what the computer is connecting to, post the wireshark logs.

        Amazon, hetzner and Evanzo are hosting providers, krebs seems to think 1337 services is a scammy site/company and thomas is a shell company. My-mail.rocks has some tor nodes.

        • melroy@kbin.melroy.org
          link
          fedilink
          arrow-up
          1
          ·
          9 days ago

          Exactly my point. Just share the actual wireshark log. You record a few seconds and then stop. And then share the log.

          • Clark@lemmy.mlOP
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            9 days ago

            I’m not just trying to get rid of the malware but also understand what it’s doing. Besides, wiping the system doesn’t help as some viruses can permanently corrupt bios. So before wiping out, I think it’s a good idea to know what’s going on my pc and where do my data go, if there is a malware. I’m a rookie with network monitoring, that’s why I’m trying to learn from more experienced users. Here is the part of the original capture: https://limewire.com/?referrer=pq7i8xx7p2. I will disable tor and close all apps along with some serviced and record again. I will let you know, thanks for your help

    • Clark@lemmy.mlOP
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      9 days ago

      Does also your computer connect to Amazon, Hetzner, 1337 Services GmbH, Evanzo GmbH and ThomasFamilyInvestments without a reason?