Solved

I need help getting info on 4 IP addresses

Posted on 2016-10-28
14
25 Views
Last Modified: 2016-10-30
I need someone who can lookup information on a few IP addresses I have. I believe they belong to the people who have been harassing me for a while now.  I just need as much information do i can take it to the PD and let then do the rest.  I know it's not that difficult I just don't know how to do it.  I have some WireShark logs as well as some Commview logs but I think I know which IPs I need researched. If anyone can help or tell me where I can get more information on them I'd be forever indebted to you.
0
Comment
Question by:Fulgencio Eres
  • 8
  • 3
  • 2
  • +1
14 Comments
 
LVL 28

Accepted Solution

by:
Jan Springer earned 250 total points
ID: 41864163
Please send them via EE mail.
0
 
LVL 30

Assisted Solution

by:pgm554
pgm554 earned 250 total points
ID: 41864183
You can easily look up IP owners using MX Toolbox.
But you chances of finding a one to one correspondence for a smoking gun are slim to none unless they have a registered static IP address.
http://mxtoolbox.com/

Use of proxy's ,unsecured wireless ,public wireless make the task near impossible except for government which has better things to do (like spy on us).
0
 
LVL 33

Expert Comment

by:paulmacd
ID: 41864213
You can run a WHOIS from most domain registrar sites.  That link points to Network Solutions.

The problem with researching an IP address only is that you'll probably get information on the ISP the address is hosted by rather than the company that's using it.
0
 

Author Comment

by:Fulgencio Eres
ID: 41864222
what piece of info should I search?
0
 

Author Comment

by:Fulgencio Eres
ID: 41864232
10.0.0.117      66.211.185.47      3      4      Out      0      https      signin.ebay.com      386      22:36:36      chrome.exe
2601:0646:8401:8da5:ad60:7a7f:c6b9:f9b0      2607:f8b0:4005:0808::200e      4      5      Out      0      https      sfo03s07-in-x0e.1e100.net      882      22:36:40      chrome.exe
2601:0646:8401:8da5:ad60:7a7f:c6b9:f9b0      2607:f8b0:4005:0806::2003      49      53      Out      3      https      sfo03s06-in-x03.1e100.net      31,003      22:39:19      chrome.exe
2601:0646:8401:8da5:ad60:7a7f:c6b9:f9b0      2607:f8b0:400e:0c00::00bc      6      6      Out      0      5228      pf-in-xbc.1e100.net      1,038      22:39:21      chrome.exe
10.0.0.117      52.71.81.247      31      32      In      0      52043      ec2-52-71-81-247.compute-1.amazonaws.com      3,574      22:39:47      ManyCam.exe
10.0.0.117      75.75.75.75      10      10      Out      0      domain      cdns01.comcast.net      2,028      22:38:45      svchost.exe
10.0.0.117      38.90.226.13      5      7      Out      1      http      38-90-226-13.ptr.eset.com      1,789      22:37:08      ekrn.exe
fe80::6442:f3ff:feca:6a8b      ff02::0001      0      32      Pass      0                    5,568      22:39:54       
10.0.0.100      239.255.255.250      0      16      Pass      0      60328, ssdp, 47786, 45608, 51728, 56787, 37604, 38564, 45821, 53626             6,264      22:39:39       
fe80::6442:f3ff:feca:6a8b      ff02::000c      0      5      Pass      0      45604, ssdp             810      22:39:06       
10.0.0.117      151.101.40.204      36      48      Out      0      http             5,646      22:36:36      chrome.exe
2601:0646:8401:8da5:ad60:7a7f:c6b9:f9b0      fe80::6442:f3ff:feca:6a8b      5      5      In      0                    860      22:39:24       
10.0.0.117      239.255.255.250      0      222      Out      0      ssdp, ws-discovery             37,312      22:39:56      svchost.exe
0
 

Author Comment

by:Fulgencio Eres
ID: 41864237
sfo03s06-in-f232.1e100.net

8.21.161.7
216.58.195.232:443
127.127.127.127
0
 

Author Comment

by:Fulgencio Eres
ID: 41864255
it's very unformatted but these are s few logs I have and can email the actual logs if anyone can help


--- Oct 27, 2016 2:05:03 AM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

Dig for 133.114.243.132

sendto failed: EDESTADDRREQ (Destination address required)
   
--------------------

--- Oct 27, 2016 1:51:41 AM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

UDP Trace to 133.114.243.132

   
--------------------

--- Oct 27, 2016 1:51:36 AM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

Dig for 133.114.243.132

sendto failed: EDESTADDRREQ (Destination address required)
   
--------------------

--- Oct 27, 2016 1:51:16 AM

Network interfaces and IPs
    wlan0 - 2601:646:8401:8da5:b819:6822:5efa:a781%6
    wlan0 - fe80::ae5f:3eff:fe94:c5de%wlan0
    wlan0 - 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
    wlan0 - 10.0.0.76
    lo - ::1%1
    lo - 127.0.0.1
    tun0 - 10.0.8.1
    p2p0 - fe80::ac5f:3eff:fe94:c5de%p2p0
    dummy0 - fe80::d465:b1ff:fe67:dba4%dummy0
    rmnet_data1 - 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
    rmnet_data1 - fe80::64d2:a229:62bc:f0ff%rmnet_data1

External IP: 50.174.162.235

MAC address is not available

Current connection type: WIFI
    WLAN: FulsFii
    DNS #1: 75.75.75.75
    DNS #2: 75.75.76.76
    Gateway: 10.0.0.1
    Mask: 255.255.255.0
    IP: 10.0.0.76
    Lease: 604800 s
    DHCP: 10.0.0.1

IP routes
10.0.0.0/24 dev wlan0  proto kernel
        scope link  src 10.0.0.76  metric 306

IP neighbors
fe80::5489:2bff:fe0a:cec3 dev wlan0
        lladdr 5c:b0:66:df:6b:dc router REACHABLE
10.0.0.1 dev wlan0
        lladdr 5c:b0:66:df:6b:dc REACHABLE
10.0.0.100 dev wlan0
        lladdr 00:90:a9:d9:0f:c6 REACHABLE

Netstat
    Proto    Recv   Send    State
    Local Address        Foreign Address
    tcp        0        0        ESTABLISHED
10.0.8.1:60741    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:56553    localhost:36838
    tcp        1        0        CLOSE_WAIT
10.0.8.1:49441    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        CLOSE_WAIT
localhost:38940    localhost:43471
    tcp        0        0        TIME_WAIT
localhost:57964    localhost:59088
    tcp        0        0        TIME_WAIT
localhost:59722    localhost:56810
    tcp        0        0        ESTABLISHED
localhost:51391    localhost:46647
    tcp        0        0        CLOSE_WAIT
localhost:43899    localhost:40214
    tcp        0        0        TIME_WAIT
localhost:33817    localhost:37213
    tcp        0        0        CLOSE_WAIT
localhost:54545    localhost:47962
    tcp        0        0        ESTABLISHED
10.0.8.1:45659    sfo03s01-in-f195.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:57769    localhost:41358
    tcp        0        0        CLOSE_WAIT
localhost:48510    localhost:40678
    tcp        0        0        ESTABLISHED
10.0.0.76:53040    ec2-52-16-99-238.eu-west-1.compute.amazonaws.co:http
    tcp        0        0        TIME_WAIT
10.0.8.1:44579    sfo07s16-in-f14.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:34546    localhost:50321
    tcp        0        0        ESTABLISHED
localhost:33455    localhost:54388
    tcp        0        0        ESTABLISHED
10.0.8.1:45660    sfo03s01-in-f195.1e100.net:https
    tcp        0        0        TIME_WAIT
localhost:53550    localhost:51597
    tcp        0        0        ESTABLISHED
localhost:43527    localhost:47556
    tcp        1        0        CLOSE_WAIT
10.0.8.1:49481    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        TIME_WAIT
localhost:33096    localhost:47045
    tcp        0        0        CLOSE_WAIT
10.0.8.1:60740    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        CLOSE_WAIT
localhost:43420    localhost:40542
    tcp        0        0        ESTABLISHED
localhost:49793    localhost:43356
    tcp        0        0        ESTABLISHED
localhost:55701    localhost:52862
    tcp        0        0        ESTABLISHED
localhost:39345    localhost:44312
    tcp        0        0        CLOSE_WAIT
localhost:37183    localhost:56310
    tcp        0        0        ESTABLISHED
localhost:60583    localhost:58232
    tcp        1        0        CLOSE_WAIT
10.0.8.1:42095    sfo03s01-in-f193.1e100.net:https
    tcp        0        0        ESTABLISHED
10.0.0.76:39175    ec2-107-20-206-176.compute-1.amazonaws.com:http
    tcp        0        0        ESTABLISHED
localhost:56091    localhost:60272
    tcp        0        0        ESTABLISHED
localhost:53727    localhost:58958
    tcp        0        0        ESTABLISHED
localhost:44312    localhost:39345
    tcp        0        0        ESTABLISHED
localhost:60272    localhost:56091
    tcp        0        0        FIN_WAIT2
localhost:47962    localhost:54545
    tcp        0        1        SYN_SENT
::ffff:10.0.8.1:42201    ec2-54-243-89-194.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
2601:646:8401:8da5:b819:6822:5efa:a781:49933    pa-in-xbc.1e100.net:5228
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:47967    ::ffff:40.76.8.142:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:36879    sfo03s01-in-f195.1e100.net:https
    tcp        1        0        CLOSE_WAIT
2601:646:8401:8da5:b819:6822:5efa:a781:35918    sfo07s13-in-x05.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:35586    edge-mqtt-mini-shv-01-sjc2.facebook.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:49488    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        0        0        ESTABLISHED
localhost:52862    localhost:55701
    tcp        0        0        ESTABLISHED
localhost:58232    localhost:60583
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:59254    sfo07s16-in-f10.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:37552    sfo07s13-in-f2.1e100.net:https
    tcp        309        0        CLOSE_WAIT
::ffff:10.0.0.76:41184    ec2-52-43-2-127.us-west-2.compute.amazonaws.co:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:45793    sfo03s01-in-f195.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:50505    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:50321    localhost:34546
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:47250    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        0        0        ESTABLISHED
2607:fb90:a4e4:521f:0:36:4ce9:2801:6201    fd00:976a:c206:3::1:65529
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:38728    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:45933    52.fc.37a9.ip4.static.sl-reverse.com:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:48923    ec2-54-225-168-155.compute-1.amazonaws.com:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:50112    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:54388    localhost:33455
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:49435    gadgets.whitepages.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:45229    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:44980    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        1        0        CLOSE_WAIT
2601:646:8401:8da5:b819:6822:5efa:a781:47507    sfo07s13-in-x05.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:50768    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:41358    localhost:57769
    tcp        0        0        FIN_WAIT2
localhost:40678    localhost:48510
    tcp        1        0        CLOSE_WAIT
2601:646:8401:8da5:b819:6822:5efa:a781:60378    sfo07s13-in-x05.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:52921    sfo03s07-in-f1.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:46647    localhost:51391
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:35019    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:42447    sfo03s07-in-f17.1e100.net:https
    tcp        304        0        CLOSE_WAIT
::ffff:10.0.0.76:49369    ec2-52-43-2-127.us-west-2.compute.amazonaws.co:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:43544    sfo07s13-in-f168.1e100.net:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:33261    sfo03s01-in-f202.1e100.net:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:56015    sfo03s06-in-f234.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:55235    sfo03s01-in-f193.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:37016    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:45289    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:46782    ::ffff:40.76.8.142:https
    tcp        0        0        TIME_WAIT
localhost:58966    localhost:45814
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:48191    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:36933    5e.fc.37a9.ip4.static.sl-reverse.com:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:33836    sfo03s01-in-f206.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:36838    localhost:56553
    tcp        0        1        SYN_SENT
::ffff:10.0.8.1:34219    ec2-54-243-89-194.compute-1.amazonaws.com:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:59210    5e.fc.37a9.ip4.static.sl-reverse.com:https
    tcp        0        0        FIN_WAIT2
localhost:40214    localhost:43899
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:53183    sfo03s01-in-f206.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:36097    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:40476    edge-mqtt-mini-shv-01-sjc2.facebook.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:49617    sfo03s01-in-f206.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:60039    sfo03s07-in-f1.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:56623    sfo07s16-in-f14.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:58958    localhost:53727
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:42843    ::ffff:74.125.170.233:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:43598    52.fc.37a9.ip4.static.sl-reverse.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:41239    sfo07s13-in-f168.1e100.net:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:45147    sfo03s01-in-f196.1e100.net:https
    tcp        0        0        FIN_WAIT2
localhost:56310    localhost:37183
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:53442    ec2-52-16-99-238.eu-west-1.compute.amazonaws.co:http
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:59943    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:55906    sfo03s01-in-f193.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:35340    5e.fc.37a9.ip4.static.sl-reverse.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:38723    sfo03s01-in-f202.1e100.net:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:52980    ec2-54-225-168-155.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:52482    sfo03s07-in-f1.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:55533    sfo03s07-in-f17.1e100.net:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:45733    server-54-192-141-29.sfo5.r.cloudfront.net:https
    tcp        1        0        CLOSE_WAIT
2601:646:8401:8da5:b819:6822:5efa:a781:57897    sfo07s13-in-x05.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:43465    edge-mqtt-mini-shv-01-sjc2.facebook.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:56340    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        TIME_WAIT
::ffff:10.0.0.76:37550    ec2-54-243-89-194.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
localhost:47556    localhost:43527
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:40179    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:43401    38.5a.17c6.ip4.static.sl-reverse.com:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:53746    sfo03s07-in-f14.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:49399    sfo07s16-in-f10.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:51345    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:40271    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:57187    ec2-107-20-206-176.compute-1.amazonaws.com:http
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:58072    sfo03s01-in-f202.1e100.net:https
    tcp        0        0        CLOSE_WAIT
::ffff:10.0.0.76:35110    5e.fc.37a9.ip4.static.sl-reverse.com:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:45439    instagram-p3-shv-01-sjc2.fbcdn.net:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:45831    ::ffff:13.107.3.128:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:53475    sfo07s16-in-f14.1e100.net:https
    tcp        0        0        TIME_WAIT
::ffff:10.0.0.76:55657    ec2-54-243-89-194.compute-1.amazonaws.com:https
    tcp        0        0        FIN_WAIT2
localhost:43471    localhost:38940
    tcp        0        0        ESTABLISHED
localhost:43356    localhost:49793

Traffic since device boot
    Mobile Bytes sent: 202,599
    Mobile Bytes rcvd: 249,483
    Total Bytes sent: 5,570,744,657
    Total Bytes rcvd: 2,612,810,348

    Mobile Packets sent: 391
    Mobile Packets rcvd: 387
    Total Packets sent: 3,953,562
    Total Packets rcvd: 2,928,347
   
--------------------

--- Oct 26, 2016 10:18:09 PM

   
--------------------


--------------------

--- Oct 26, 2016 10:17:42 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

URL: http://8.21.161.7/

Problem accessing URL: failed to connect to /8.21.161.7 (port 80) after 5000ms
   
--------------------

--- Oct 26, 2016 10:17:06 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

UDP Trace to 8.21.161.7

1  10.0.0.1
      12.601 ms  13.340 ms  11.896 ms
   
--------------------

--- Oct 26, 2016 10:16:12 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

Reverse DNS on 8.21.161.7:

tunnel.cfw.trustedsource.org.

(DNS server: 8.8.8.8, port 53, TCP)

   
--------------------

--- Oct 26, 2016 10:16:08 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

DNS records for 8.21.161.7

A   host not found

AAAA   host not found

(DNS server: 8.8.8.8, port 53, TCP)

   
--------------------

--- Oct 26, 2016 10:15:51 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

--- using GPS location
PING 8.21.161.7 (8.21.161.7) 56(84) bytes of data.

--- 8.21.161.7 ping statistics ---
3 packets transmitted, 0 received, 100% packet loss, time 2002ms

   
--------------------

--- Oct 26, 2016 10:15:16 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

UDP Trace to 8.21.161.7

   
--------------------

--- Oct 26, 2016 10:06:47 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

Whois 8.21.161.7
   
--------------------

--- Oct 26, 2016 10:06:43 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

Dig for 8.21.161.7

sendto failed: EDESTADDRREQ (Destination address required)
   
--------------------

--- Oct 26, 2016 10:06:35 PM

Network interfaces and IPs
    wlan0 - 2601:646:8401:8da5:b819:6822:5efa:a781%6
    wlan0 - fe80::ae5f:3eff:fe94:c5de%wlan0
    wlan0 - 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
    wlan0 - 10.0.0.76
    lo - ::1%1
    lo - 127.0.0.1
    tun0 - 10.0.8.1
    p2p0 - fe80::ac5f:3eff:fe94:c5de%p2p0
    dummy0 - fe80::d465:b1ff:fe67:dba4%dummy0
    rmnet_data1 - 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
    rmnet_data1 - fe80::64d2:a229:62bc:f0ff%rmnet_data1

External IP: 50.174.162.235

MAC address is not available

Current connection type: WIFI
    WLAN: FulsFii
    DNS #1: 75.75.75.75
    DNS #2: 75.75.76.76
    Gateway: 10.0.0.1
    Mask: 255.255.255.0
    IP: 10.0.0.76
    Lease: 604800 s
    DHCP: 10.0.0.1

IP routes
10.0.0.0/24 dev wlan0  proto kernel
        scope link  src 10.0.0.76  metric 306

IP neighbors
fe80::5489:2bff:fe0a:cec3 dev wlan0
        lladdr 5c:b0:66:df:6b:dc router REACHABLE

Netstat
    Proto    Recv   Send    State
    Local Address        Foreign Address
    tcp        0        0        ESTABLISHED
localhost:38360    localhost:37452
    tcp        0        0        ESTABLISHED
localhost:41992    localhost:51132
    tcp        0        0        ESTABLISHED
10.0.8.1:36553    sfo07s16-in-f6.1e100.net:https
    tcp        0        0        ESTABLISHED
10.0.0.76:38092    ec2-54-225-140-11.compute-1.amazonaws.com:http
    tcp        0        0        ESTABLISHED
localhost:43528    localhost:43064
    tcp        0        0        ESTABLISHED
10.0.8.1:45027    sfo07s16-in-f2.1e100.net:https
    tcp        0        0        CLOSE_WAIT
localhost:49375    localhost:46171
    tcp        0        0        ESTABLISHED
localhost:55396    localhost:45248
    tcp        0        0        TIME_WAIT
localhost:52316    localhost:34984
    tcp        0        0        ESTABLISHED
10.0.8.1:47752    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:37446    localhost:41401
    tcp        0        0        ESTABLISHED
localhost:53106    localhost:52701
    tcp        0        0        ESTABLISHED
localhost:53373    localhost:42594
    tcp        0        0        ESTABLISHED
10.0.8.1:49482    sfo03s07-in-f14.1e100.net:https
    tcp        0        0        ESTABLISHED
10.0.8.1:49484    sfo03s07-in-f14.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:55158    localhost:46515
    tcp        0        0        ESTABLISHED
10.0.8.1:47660    sfo03s01-in-f206.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:53542    localhost:38387
    tcp        0        0        ESTABLISHED
localhost:38764    localhost:47026
    tcp        0        0        ESTABLISHED
localhost:45208    localhost:44271
    tcp        0        0        ESTABLISHED
10.0.8.1:45028    sfo07s16-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
10.0.8.1:47755    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
10.0.8.1:55479    pc-in-f94.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:34696    localhost:43470
    tcp        0        0        ESTABLISHED
localhost:42843    localhost:42635
    tcp        0        0        CLOSE_WAIT
localhost:59981    localhost:54253
    tcp        0        0        ESTABLISHED
localhost:43631    localhost:45004
    tcp        0        0        ESTABLISHED
10.0.8.1:36552    sfo07s16-in-f6.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:46142    localhost:33667
    tcp        0        0        ESTABLISHED
10.0.8.1:36565    sfo07s16-in-f6.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:43132    localhost:52089
    tcp        0        0        ESTABLISHED
10.0.8.1:55481    pc-in-f94.1e100.net:https
    tcp        0        0        ESTABLISHED
2601:646:8401:8da5:b819:6822:5efa:a781:56635    edge-mqtt-mini6-shv-01-sjc2.facebook.com:https
    tcp        0        0        ESTABLISHED
2601:646:8401:8da5:b819:6822:5efa:a781:49933    pa-in-xbc.1e100.net:5228
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:60339    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:51132    localhost:41992
    tcp        0        0        ESTABLISHED
localhost:37452    localhost:38360
    tcp        0        0        ESTABLISHED
localhost:46515    localhost:55158
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:47582    sfo03s01-in-f198.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:44866    ec2-54-225-216-218.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:42580    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:52701    localhost:53106
    tcp        0        0        ESTABLISHED
localhost:42635    localhost:42843
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:33989    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:40278    sfo03s01-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
2607:fb90:a4e4:521f:0:36:4ce9:2801:6201    fd00:976a:c206:3::1:65529
    tcp        0        0        ESTABLISHED
localhost:43470    localhost:34696
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:49435    gadgets.whitepages.com:https
    tcp        0        0        ESTABLISHED
localhost:47026    localhost:38764
    tcp        0        0        ESTABLISHED
localhost:45004    localhost:43631
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:58257    sfo07s16-in-f2.1e100.net:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:58678    ec2-107-22-216-237.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:34808    sfo07s16-in-f6.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:46511    ec2-54-225-140-11.compute-1.amazonaws.com:http
    tcp        0        0        ESTABLISHED
localhost:45248    localhost:55396
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.0.76:40716    vip098.ssl.hwcdn.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:33971    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
2601:646:8401:8da5:b819:6822:5efa:a781:60358    sfo03s07-in-x0a.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:60475    sfo03s01-in-f206.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:37819    sfo07s16-in-f6.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:41401    localhost:37446
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:51190    sfo03s01-in-f206.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:57140    sfo07s16-in-f6.1e100.net:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:48376    ec2-54-243-89-194.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:50295    sfo03s07-in-f14.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:39541    sfo07s13-in-f168.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:33667    localhost:46142
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:34186    pc-in-f94.1e100.net:https
    tcp        32        0        CLOSE_WAIT
::ffff:10.0.8.1:54184    reverse-unset.bbu.exdc01.bitdefender.net:https
    tcp        0        0        ESTABLISHED
localhost:42594    localhost:53373
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:52183    ec2-52-16-99-238.eu-west-1.compute.amazonaws.co:http
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:42414    sfo07s16-in-f14.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:53280    pc-in-f94.1e100.net:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:53408    sfo03s01-in-f206.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:36224    sfo07s13-in-f2.1e100.net:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:50935    ns3033426.ip-149-202-92.eu:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:47251    sfo07s16-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:35464    ec2-54-225-216-218.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.8.1:56293    sfo07s13-in-f2.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:43064    localhost:43528
    tcp        0        0        ESTABLISHED
localhost:44271    localhost:45208
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:53746    sfo03s07-in-f14.1e100.net:https
    tcp        0        0        ESTABLISHED
2607:fb90:a4e4:521f:0:36:4ce9:2801:39397    fd00:976a:c206:3::1:sip
    tcp        0        0        ESTABLISHED
localhost:52089    localhost:43132
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:46307    sfo03s07-in-f14.1e100.net:https
    tcp        1        0        CLOSE_WAIT
::ffff:10.0.0.76:54877    ec2-54-243-89-194.compute-1.amazonaws.com:https
    tcp        0        0        ESTABLISHED
2601:646:8401:8da5:b819:6822:5efa:a781:59694    sfo07s16-in-x02.1e100.net:https
    tcp        0        0        ESTABLISHED
::ffff:10.0.0.76:37160    sfo07s13-in-f168.1e100.net:https
    tcp        0        0        ESTABLISHED
localhost:38387    localhost:53542

Traffic since device boot
    Mobile Bytes sent: 94,228
    Mobile Bytes rcvd: 128,557
    Total Bytes sent: 314,267,652
    Total Bytes rcvd: 582,665,490

    Mobile Packets sent: 176
    Mobile Packets rcvd: 181
    Total Packets sent: 260,534
    Total Packets rcvd: 400,968
   
--------------------

--- Oct 26, 2016 10:06:19 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

--- using GPS location
PING 8.21.161.7 (8.21.161.7) 56(84) bytes of data.

--- 8.21.161.7 ping statistics ---
3 packets transmitted, 0 received, 100% packet loss, time 2008ms

   
--------------------

--- Oct 26, 2016 10:06:13 PM
--- IP (wlan0) 2601:646:8401:8da5:b819:6822:5efa:a781%6
--- IP (wlan0) fe80::ae5f:3eff:fe94:c5de%wlan0
--- IP (wlan0) 2601:646:8401:8da5:ae5f:3eff:fe94:c5de%6
--- IP (wlan0) 10.0.0.76
--- IP (tun0) 10.0.8.1
--- IP (dummy0) fe80::d465:b1ff:fe67:dba4%dummy0
--- IP (rmnet_data1) 2607:fb90:a4e4:521f:0:36:4ce9:2801%8
--- IP (rmnet_data1) fe80::64d2:a229:62bc:f0ff%rmnet_data1
--- Connection: WIFI

--- using GPS location
   


LAN Hosts (MAC) Report
Generated on 10/28/2016 at 12:04:22 AM
MAC/Alias      Pkts Sent      Pkts Rec.      Bytes Sent      Bytes Rec.      B-casts      M-casts
5C:B0:66:DF:6B:D9      56      61      4,066      3,682      0      0
5C:B0:66:DF:6B:DC      1,293,010      900,725      1,573,288,245      694,136,831      53      5,057
BenuNetw:01:18:10      909      953      387,121      128,815      0      0
Broadcast      0      3,890      0      194,626      0      0
GroupedMulticast      0      21,059      0      6,478,749      0      0
HonHaiPr:31:CF:19      45,884,437      5,910,015      68,725,724,010      1,878,199,962      1,882      11,796
LiteonTe:7F:95:0D      10,235      6,141      3,154,432      588,429      3      86
MurataMa:99:96:4F      6      9      252      514      0      0
NarayInf:03:02:01      1      0      86      0      0      1
SamsungE:94:C5:DE      2,328      283      114,188      12,838      1,889      375
WesternD:D9:0F:C6      4,614,741      44,962,587      303,748,470      68,026,676,424      63      3,744

This report was generated by CommView.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 33

Expert Comment

by:paulmacd
ID: 41864256
sfo03s06-in-f232.1e100.net <- Some reputation-monitoring site

8.21.161.7 <- McAfee Antivirus
216.58.195.232:443  <- Google
127.127.127.127 <- Loopback/not a public address

What are the odds you're imagining things?
0
 

Author Comment

by:Fulgencio Eres
ID: 41864264
==================================================
IP Address        : 10.0.0.217
Device Name       :
MAC Address       : 98-F1-70-99-96-4F
Network Adapter Company: Murata Manufacturing Co., Ltd.
Device Information:
User Text         :
First Detected On : 10/9/2016 12:43:47 PM
Last Detected On  : 10/9/2016 12:44:34 PM
Detection Count   : 1
Active            : No
==================================================
0
 
LVL 30

Expert Comment

by:pgm554
ID: 41864290
A 10 subnet is a private non routable address range usually reserved for in house IP addressing.
So I'm not quite sure as to what you are looking for.
0
 

Author Comment

by:Fulgencio Eres
ID: 41864651
slim to none.. how were you able to get that information?is there a website or app i can use to search more?  when I'm going thru the logs is there anything in particular that I should look out for? (red flags)
0
 
LVL 30

Expert Comment

by:pgm554
ID: 41864725
Please describe why you think you are being harassed from an IP address?
0
 

Author Comment

by:Fulgencio Eres
ID: 41865582
I know that they've been in my phone and computer because of various things being changed/ deleted and they have approached me for ransom... I have so much information but I just don't know how to read it
0
 

Author Closing Comment

by:Fulgencio Eres
ID: 41865915
I'm not able to find ur email address...how can I get them to you?
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Network ports are the threads that hold network communication together. They are an essential part of networking that can be easily ignore or misunderstood, my goals is to show those who don't have a strong network foundation how network ports opera…
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now