AndyPandaX
asked on
Packet Sniffer or Logs on Server to identify who connects to what
Hi all,
We have identitfied that one of the PCs on our network has S_Nethelper.
The IP addresses this is connecting to is 212.227.252.196 / preffeddns.info. Is there something I can install on the server thats both free and relativley simple to idenity which local IP address is connecting to the above, or is it possible to look at the servers DNS logs to see which local IP has done a lookup on the domain name? If it is, how do i do that please?
Basically I just need to find which local device is trying to connect to the above IP and I dont know how to.
Regards
We have identitfied that one of the PCs on our network has S_Nethelper.
The IP addresses this is connecting to is 212.227.252.196 / preffeddns.info. Is there something I can install on the server thats both free and relativley simple to idenity which local IP address is connecting to the above, or is it possible to look at the servers DNS logs to see which local IP has done a lookup on the domain name? If it is, how do i do that please?
Basically I just need to find which local device is trying to connect to the above IP and I dont know how to.
Regards
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
other way one or many of your computes is infected with a virus that most AV software detects
https://www.virustotal.com/en/ip-address/212.227.252.196/information/
https://www.virustotal.com/en/ip-address/212.227.252.196/information/
It would be far simpler to use nestat -nab |more at the command prompt to see where connections are coming from/going to.
I use Comm View (Excellent) and Wire Shark works as well.