Link to home
Start Free TrialLog in
Avatar of AndyPandaX
AndyPandaX

asked on

Packet Sniffer or Logs on Server to identify who connects to what

Hi all,

We have identitfied that one of the PCs on our network has S_Nethelper.

The IP addresses this is connecting to is 212.227.252.196 / preffeddns.info. Is there something I can install on the server thats both free and relativley simple to idenity which local IP address is connecting to the above, or is it possible to look at the servers DNS logs to see which local IP has done a lookup on the domain name? If it is, how do i do that please?

Basically I just need to find which local device is trying to connect to the above IP and I dont know how to.

Regards
ASKER CERTIFIED SOLUTION
Avatar of jhyiesla
jhyiesla
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
A good packet sniffer works and gives you information as shown below. It shows IP addresses in and out and so shows what is connected to what. Look for you IP in this and see what it is connected to.

I use Comm View (Excellent) and Wire Shark works as well.

User generated image
other way one or many of your computes is infected with a virus that most AV software detects
https://www.virustotal.com/en/ip-address/212.227.252.196/information/
Avatar of Calvin Paxson
Calvin Paxson

It would be far simpler to use nestat -nab |more at the command prompt to see where connections are coming from/going to.