๐ Ran netstat...do these "phone home"?
๐ก Newskategorie: IT Security Nachrichten
๐ Quelle: reddit.com
This is part 2 to my earlier post:
I ran netstat and got the following. I was unable to necessarily trace all the IP addresses. Are any of these concerns in that they might be "phoning home" to my spouse's old employer's servers? TIA!
โ
Microsoft Windows [Version 10.0.19041.450] (c) 2020 Microsoft Corporation. All rights reserved. C:\Windows\system32>netstat -a -b -n Active Connections Proto Local Address Foreign Address State TCP 0.0.0.0:135 0.0.0.0:0 LISTENING RpcSs [svchost.exe] TCP 0.0.0.0:445 0.0.0.0:0 LISTENING Can not obtain ownership information TCP 0.0.0.0:623 0.0.0.0:0 LISTENING [LMS.exe] TCP 0.0.0.0:808 0.0.0.0:0 LISTENING [OneApp.IGCC.WinService.exe] TCP 0.0.0.0:5040 0.0.0.0:0 LISTENING CDPSvc [svchost.exe] TCP 0.0.0.0:9001 0.0.0.0:0 LISTENING Can not obtain ownership information TCP 0.0.0.0:16992 0.0.0.0:0 LISTENING [LMS.exe] TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING [lsass.exe] TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING Can not obtain ownership information TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING Schedule [svchost.exe] TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING EventLog [svchost.exe] TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING [spoolsv.exe] TCP 0.0.0.0:49670 0.0.0.0:0 LISTENING Can not obtain ownership information TCP 127.0.0.1:49671 0.0.0.0:0 LISTENING [LMS.exe] TCP 127.0.0.1:49672 127.0.0.1:49673 ESTABLISHED [LMS.exe] TCP 127.0.0.1:49673 127.0.0.1:49672 ESTABLISHED [LMS.exe] TCP 127.0.0.1:51250 127.0.0.1:49671 TIME_WAIT TCP 192.168.7.118:139 0.0.0.0:0 LISTENING Can not obtain ownership information TCP 192.168.7.118:49681 204.79.197.200:443 TIME_WAIT TCP 192.168.7.118:49682 13.107.19.254:443 TIME_WAIT TCP 192.168.7.118:49683 13.107.42.254:443 TIME_WAIT TCP 192.168.7.118:49685 13.107.4.254:443 TIME_WAIT TCP 192.168.7.118:49686 13.107.255.58:443 TIME_WAIT TCP 192.168.7.118:49687 51.140.152.167:443 TIME_WAIT TCP 192.168.7.118:49688 72.21.81.200:443 TIME_WAIT TCP 192.168.7.118:49689 13.107.3.254:443 TIME_WAIT TCP 192.168.7.118:49690 204.79.197.254:443 TIME_WAIT TCP 192.168.7.118:49691 13.107.6.254:443 TIME_WAIT TCP 192.168.7.118:51231 192.168.1.1:53 TIME_WAIT TCP 192.168.7.118:51233 137.135.96.104:443 ESTABLISHED Can not obtain ownership information TCP 192.168.7.118:51234 13.107.4.52:80 TIME_WAIT TCP 192.168.7.118:51238 23.4.6.168:80 TIME_WAIT TCP 192.168.7.118:51245 23.4.8.81:443 ESTABLISHED WpnUserService_314e6 [svchost.exe] TCP 192.168.7.118:51247 23.4.6.168:80 ESTABLISHED WpnUserService_314e6 [svchost.exe] TCP 192.168.7.118:51272 204.79.197.200:443 ESTABLISHED [SearchApp.exe] TCP 192.168.7.118:51279 40.90.22.185:443 ESTABLISHED [OneDrive.exe] TCP 192.168.7.118:51280 52.86.141.238:80 TIME_WAIT TCP 192.168.7.118:51282 13.107.246.10:443 ESTABLISHED [OneDrive.exe] TCP 192.168.7.118:51283 13.107.246.10:443 ESTABLISHED [OneDrive.exe] TCP 192.168.7.118:51284 52.86.141.238:80 TIME_WAIT TCP 192.168.7.118:51286 204.79.197.222:443 ESTABLISHED [SearchApp.exe] TCP 192.168.7.118:51287 13.107.19.254:443 ESTABLISHED [SearchApp.exe] TCP 192.168.7.118:51288 131.253.33.254:443 ESTABLISHED [SearchApp.exe] TCP 192.168.7.118:51289 13.107.246.10:443 ESTABLISHED [SearchApp.exe] TCP 192.168.7.118:62523 192.168.1.1:53 TIME_WAIT TCP 192.168.7.118:62524 168.61.144.12:443 TIME_WAIT TCP 192.168.7.118:62525 13.107.255.56:443 TIME_WAIT TCP [::]:135 [::]:0 LISTENING RpcSs [svchost.exe] TCP [::]:445 [::]:0 LISTENING Can not obtain ownership information TCP [::]:623 [::]:0 LISTENING [LMS.exe] TCP [::]:808 [::]:0 LISTENING [OneApp.IGCC.WinService.exe] TCP [::]:9001 [::]:0 LISTENING Can not obtain ownership information TCP [::]:16992 [::]:0 LISTENING [LMS.exe] TCP [::]:49664 [::]:0 LISTENING [lsass.exe] TCP [::]:49665 [::]:0 LISTENING Can not obtain ownership information TCP [::]:49666 [::]:0 LISTENING Schedule [svchost.exe] TCP [::]:49667 [::]:0 LISTENING EventLog [svchost.exe] TCP [::]:49668 [::]:0 LISTENING [spoolsv.exe] TCP [::]:49670 [::]:0 LISTENING Can not obtain ownership information TCP [::1]:49669 [::]:0 LISTENING [jhi_service.exe] TCP [::1]:49674 [::1]:16992 TIME_WAIT TCP [::1]:49675 [::1]:16992 TIME_WAIT TCP [::1]:49676 [::1]:16992 TIME_WAIT TCP [::1]:49677 [::1]:16992 TIME_WAIT TCP [::1]:49678 [::1]:16992 TIME_WAIT TCP [::1]:49679 [::1]:16992 TIME_WAIT TCP [::1]:49680 [::1]:16992 TIME_WAIT TCP [::1]:51235 [::1]:16992 TIME_WAIT TCP [::1]:51236 [::1]:16992 TIME_WAIT TCP [::1]:51237 [::1]:16992 TIME_WAIT TCP [::1]:51239 [::1]:16992 TIME_WAIT TCP [::1]:51240 [::1]:16992 TIME_WAIT TCP [::1]:51241 [::1]:16992 TIME_WAIT TCP [::1]:51242 [::1]:16992 TIME_WAIT TCP [::1]:51243 [::1]:16992 TIME_WAIT TCP [::1]:51244 [::1]:16992 TIME_WAIT TCP [::1]:51246 [::1]:16992 TIME_WAIT TCP [::1]:51248 [::1]:16992 TIME_WAIT TCP [::1]:51249 [::1]:16992 TIME_WAIT TCP [::1]:51251 [::1]:16992 TIME_WAIT TCP [::1]:51252 [::1]:16992 TIME_WAIT TCP [::1]:51253 [::1]:16992 TIME_WAIT TCP [::1]:51254 [::1]:16992 TIME_WAIT TCP [::1]:51255 [::1]:16992 TIME_WAIT TCP [::1]:51256 [::1]:16992 TIME_WAIT TCP [::1]:51257 [::1]:16992 TIME_WAIT TCP [::1]:51258 [::1]:16992 TIME_WAIT TCP [::1]:51259 [::1]:16992 TIME_WAIT TCP [::1]:51260 [::1]:16992 TIME_WAIT TCP [::1]:51261 [::1]:16992 TIME_WAIT TCP [::1]:51262 [::1]:16992 TIME_WAIT TCP [::1]:51263 [::1]:16992 TIME_WAIT TCP [::1]:51264 [::1]:16992 TIME_WAIT TCP [::1]:51265 [::1]:16992 TIME_WAIT TCP [::1]:51266 [::1]:16992 TIME_WAIT TCP [::1]:51267 [::1]:16992 TIME_WAIT TCP [::1]:51268 [::1]:16992 TIME_WAIT TCP [::1]:51269 [::1]:16992 TIME_WAIT TCP [::1]:51270 [::1]:16992 TIME_WAIT TCP [::1]:51271 [::1]:16992 TIME_WAIT TCP [::1]:51273 [::1]:16992 TIME_WAIT TCP [::1]:51274 [::1]:16992 TIME_WAIT TCP [::1]:51275 [::1]:16992 TIME_WAIT TCP [::1]:51276 [::1]:16992 TIME_WAIT TCP [::1]:51277 [::1]:16992 TIME_WAIT UDP 0.0.0.0:5050 *:* CDPSvc [svchost.exe] UDP 0.0.0.0:5353 *:* Dnscache [svchost.exe] UDP 0.0.0.0:5355 *:* Dnscache [svchost.exe] UDP 127.0.0.1:49664 *:* iphlpsvc [svchost.exe] UDP 192.168.7.118:137 *:* Can not obtain ownership information UDP 192.168.7.118:138 *:* Can not obtain ownership information UDP [::]:5353 *:* Dnscache [svchost.exe] UDP [::]:5355 *:* Dnscache [svchost.exe] UDP [fe80::d018:8c9:a0f1:3182%4]:546 *:* Dhcp [svchost.exe] C:\Windows\system32>
[link] [comments] ...