Hello all,

According to the Wireshark record my computer connects to various services often, including Amazon, Hetzner, 1337 Services GmbH, Evanzo GmbH and ThomasFamilyInvestments. The most often were the connections to mail.my-mail.rocks which is a part of Netcup GmbH. I have a somewhat minimal distro and the attached recordings were made when no app was open including no browser. I can send the other screenshots showing other connections too. I’m suspecting of malware since some time ago but can you help me clarify these connections please?

  • stupid_asshole69 [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    5
    ·
    20 days ago

    That screenshot just looks like a computer (.100, is that you?) dialing the upstream device (a zyxel!), it doesn’t seem to show what the intended recipient is. If you’re running windows then the start menu ads do crazy stuff. Also I asked if that last local ip octet is you because wireshark will show you other computers traffic coming across its wireless interface.

    From a high port to a low port makes me think it’s someone else on your network doing piracy.

    • Clark@lemmy.mlOP
      link
      fedilink
      arrow-up
      2
      ·
      20 days ago

      Yes, .100 is me. I have a Zyxel router, should it show the intended recipient? I’m running Linux. What do you mean by a high port to a low port? I also think there is a malware.

      • stupid_asshole69 [none/use name]@hexbear.net
        link
        fedilink
        English
        arrow-up
        3
        ·
        20 days ago

        If you think there’s malware then just wipe and reinstall.

        If you wanna find out what the computer is connecting to, post the wireshark logs.

        Amazon, hetzner and Evanzo are hosting providers, krebs seems to think 1337 services is a scammy site/company and thomas is a shell company. My-mail.rocks has some tor nodes.