Are my captured TCP, DNS packages flagged as SYN, ACK (etc) suspicious?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • watreen
    New Member
    • Feb 2010
    • 2

    Are my captured TCP, DNS packages flagged as SYN, ACK (etc) suspicious?

    Iam really concered about this traffic captured by Wireshark. Since today
    I get a lot of TCP packages although no program is interacting with internet.
    There are ARP's, SYNs and my computer even sends back a lot of ACK packages. Few Http and DNS were captured aswell.

    Source IP's coming among others from
    (1) USA Redmon 207.46.198.220 (Microsoft) *maybe abused
    (2) UK 94.236.15.26 (rackspace.com)
    (3) USA New Orleans 66.157.50.237 (BellSouth.net Inc.)

    I attached one jpg for a quick overview and one zip file including the complete
    capture.

    I've to mention that iam not a network adminstrator. This is my private family
    computer located behind an ethernet router.

    Hopefully there is a harmless reason for this suspicious capturing.

    Kind regards,
    watreen
    Attached Files
  • watreen
    New Member
    • Feb 2010
    • 2

    #2
    I think I found out what's causing this traffic. I found some link refering to a weather radar website. That lead me to my gadgets on Windows. After closing them I didnt found any traffic going on between my computer and other network adresses. Just to be on the safe side I will do tomorrow again some monitoring.

    Bye -
    Watreen

    Comment

    • sicarie
      Recognized Expert Specialist
      • Nov 2006
      • 4677

      #3
      Good catch, and thanks for posting the resolution!

      Comment

      Working...