The Issue and my Concern:
Hi all, I had a question about some Wireshark results I've been getting lately. I have been getting a ton of Skype connections when running Wireshark. This is strange because I've never used Skype and don't have it installed. I've looked up the IP addresses that I'm connected to and couldn't find anything on them. It made me wonder about a possible hacking attempt or some kind of remote connection from malware. I have been downloading from torrents lately and I got lazy and didn't scan them like I usually do so I wondered if perhaps I downloaded some kind of trojan or something along with the files.
What I Did to Try to Figure out What's Going On:
I do have the LBRY app running in the background and I've wondered if that could be what Wireshark is picking up, just misidentifying the traffic. To test this I shutdown LBRY and confirmed that no instances were running with netstat and htop while running Wireshark and there does seem to be a large decrease in Skype packets, but they still come through, just about 80% less when I shut down LBRY. Then I restarted LBRY and the flood of alleged Skype packed spiked again in Wireshark.
This makes me wonder if Wireshark is merely misidentifying the traffic as Skype, but why do those connections persist when the app and the connections are shut down and don't show up in the netstat and htop results? I was wondering if perhaps someone could be hiding their hacking attempts in traffic they saw from my machine. I’m still learning about this kind of stuff and I’m not sure if that’s realistic.
I also ran rkhunter and chkrootkit and I know these apps are more for servers since files change so often on Desktop Linux but I figured I'd cover my bases. rkhunter said it found 6 rootkits. That number is very high from when I've run it in the past. Usually I'll only get 1 or 2 confirmed false positives, but 6? Again, I was wondering if there may be a few false positives and maybe I had downloaded something bad.
After writing all this out I am feeling better about my theory that it’s most likely the LBRY app running in the background but I suppose I am just paranoid and want to be sure if my instincts are correct and want to see what others think.
Anyone else use the LBRY app and get the same results? I attached a screenshot of a small portion of the results for reference.
Bookmarks