@Gertjan said in Normal traffic graph in "idle"?:
A Windows OS ? You ever heard about telemetry data ? The keylogger you installed on your PC
It's Ubuntu though ;)
@Gertjan said in Normal traffic graph in "idle"?:
What is that ?
A website to check what is behind an IP. For example:
https://otx.alienvault.com/indicator/ip/34.149.144.89
@Gertjan said in Normal traffic graph in "idle"?:
That's your browser doing auto-captive-portal detection. This is port destination 80 TCP traffic, right ?
Yep port 80 traffic
@Gertjan said in Normal traffic graph in "idle"?:
You were actually using all this stuff all the time. It's always a good thing to find out how things work.
I am still trying to figure things out. I haven't gotten into the packet capture part yet. Only superficially by checking Snort captures. I also googled what TCP Dup ACK is but I don't know if it is something to worry about or a normal occurance. The last couple of days I saw 3 out of 5 Windows computers make outgoing connections to malicious IPs that are flagged on otx.alienvault and it makes me worried. Even on a fresh Windows install I had this happen by a service that should only communicate on LAN (Windows LanmanServer). I just blocked the whole IP range to be safe. It was also blocked by Snort with "ET INFO Packed Executable Download", Misc activity 3. I hope it's just a false positive.
@stephenw10 said in Normal traffic graph in "idle"?:
No. The source and destination are stll the same.
Ok great. Thank you :)