some strange network connections to public ip 192.162.1.1 outbound on port 445 from system Process

Anonymous
2024-09-22T06:43:33+00:00

Dear All,

greetings!

i can see some strange network connections to public ip 192.162.1.1 outbound on port 445 i didn't find any possible explanation ,

I captured the traffic from netmon and able to see process is system initiated,

as checked in full av scan no suspicious programs are detected.

can some one please help me the reason for the traffic.

thank you.

Windows Server | Networking

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2024-09-23T07:23:39+00:00

    Hello,

    Thank you for posting in Microsoft Community forum.

    Seeing that the network you mentioned is connected to the public IP address 192.162.1.1 and is sent out over port 445, this is really a concern. Here are some possible causes and troubleshooting steps:

    1. Port 445 is commonly used for Microsoft's SMB protocol and is primarily used for file sharing and printing services. If you're seeing system-initiated connections, it could be one of the following reasons:

    File sharing: If file sharing is enabled on your computer, you might try to connect to another device.

    Malware: Although you have a comprehensive virus scan, some malware may masquerade as a system process or use other methods to hide its activity.

    1. If you don't need file sharing, you can disable file and print sharing in Control Panel.
    2. Use a network monitoring tool to further analyze traffic and see what specific requests and responses are being made to understand the purpose of the connection.

    Use a tool, such as Process Explorer, to view the specific process associated with the connection and confirm that it is a system process.

    1. Open the Event Viewer and check the system and security logs for unusual events related to the network connection.
    2. Ensure that the operating system and all software are up-to-date to prevent known vulnerabilities from being exploited.
    3. If possible, check the logs of your router and other network devices to confirm that there is no unusual activity.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Regards,

    Jill Zhou

    0 comments No comments
  2. Anonymous
    2024-09-30T10:42:34+00:00

    Dear Mr. Zhou,

    thank you so much for the reply,

    As you mentioned above we have checked all the points,

    there is no abnormal programs,

    the traffic is just a bunch of events and there after there is no trace,

    we have captured some of the events from resource monitor which is greyed out as below and we have also netmon capture if yes i can share explicitly.

    any help to fins this root cause is highly appreciated.

    Just fyi.. this server is used as a central log collection from multiple servers which uses SMB indeed.

    thank you.

    0 comments No comments