I capture unwanted traffic to ip whois LIQUIDWEB. How do i trace source?

asked 2017-12-05

anonymous user


updated 2017-12-05

grahamb gravatar image


1354    164.030569    TCP 54  0.000073000 41  53843 → 443 [ACK] Seq=1 Ack=1 Win=65700 Len=0

How can i stop this? How to find source on my PC?


1 Answer

answered 2017-12-06

Rooster_50 gravatar image

Run cmd.exe as administrator and type "netstat -abn". Look for the socket you are inquiring about. The command will also list the executable that created the connection.

Were you capturing from a span or tap? Or was this traffic in an out of your own box?

masonke ( 2017-12-06 )

