Relvox Posted April 8, 2012 Report Share Posted April 8, 2012 Heya, I've been hunting for malware on my computer today when I noticed that utorrent tried to send a lot of requests to a domian called ferrishyn.com (ip 173.45.162.164).I'm curious, why would uTorrent do that?Relvox Link to comment Share on other sites More sharing options...
kotekzot Posted April 8, 2012 Report Share Posted April 8, 2012 probably a tracker or a peer. Link to comment Share on other sites More sharing options...
Relvox Posted April 8, 2012 Author Report Share Posted April 8, 2012 First of all, I notice that there are more connections made to that ip than all other ips combined.Second of all, I notice that the bulk of connections are opened when I try to close utorrent.Anyone else has seen that happening / has any clues? Link to comment Share on other sites More sharing options...
kotekzot Posted April 9, 2012 Report Share Posted April 9, 2012 if you think something's up run some malware scans. this is on your end, otherwise firon'd wake up to a pitchforked mob. Link to comment Share on other sites More sharing options...
Relvox Posted April 10, 2012 Author Report Share Posted April 10, 2012 malware scans show nothing, reinstalling utorrent changes nothing ... nobody else getting this? Link to comment Share on other sites More sharing options...
DreadWingKnight Posted April 10, 2012 Report Share Posted April 10, 2012 Did you bother trying to packetsniff to see what the traffic actually was? Link to comment Share on other sites More sharing options...
Relvox Posted April 10, 2012 Author Report Share Posted April 10, 2012 Did you bother trying to packetsniff to see what the traffic actually was?Pretty stupid of me not to, I will do so now! Link to comment Share on other sites More sharing options...
Firon Posted April 10, 2012 Report Share Posted April 10, 2012 You do realize P2P clients will connect to all sorts of random IPs, right? Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.