关于netstat -b输出的网络连接是否存在入侵风险的咨询
关于netstat -b输出的网络连接是否存在入侵风险的咨询
Hey there, let's walk through your netstat -b output step by step to put your mind at ease:
First, here's the output you shared for reference:
C:\Windows\system32>netstat -b Active Connections Proto Local Address Foreign Address State TCP 192.168.4.131:49670 104.18.35.23:https ESTABLISHED [msedge.exe] TCP 192.168.4.131:49780 47:https ESTABLISHED [msedge.exe] TCP 192.168.4.131:50226 104.18.40.222:https TIME_WAIT TCP 192.168.4.131:50286 160:https ESTABLISHED [msedge.exe] TCP 192.168.4.131:50635 13.69.239.74:https ESTABLISHED [msedge.exe] TCP 192.168.4.131:50986 104.18.35.23:https ESTABLISHED [msedge.exe] TCP 192.168.4.131:51013 a23-63-180-17:https ESTABLISHED [msedge.exe] TCP 192.168.4.131:51965 104.18.41.33:https TIME_WAIT TCP 192.168.4.131:52513 52.238.235.86:https CLOSE_WAIT [SystemSettings.exe] TCP 192.168.4.131:53543 101:https ...
Now, let's break down what this means:
- Most active connections are from
msedge.exe: This is your Microsoft Edge browser, and these connections are completely normal. Every time you open a website, load images, sync browser data, or even have tabs running in the background, Edge establishes HTTPS connections to web servers. The incomplete foreign addresses (like47:httpsor160:https) are just temporary DNS resolution glitches—nothing to worry about, since the process is still your legitimate browser. - TIME_WAIT state connections: These are connections that have recently closed. The TIME_WAIT state is a standard part of TCP's connection cleanup process, ensuring all data is fully transmitted before the connection is fully terminated. No red flags here.
- CLOSE_WAIT connection from
SystemSettings.exe: This is Windows' System Settings app. It likely established this connection to check for system updates, sync your Microsoft account settings, or access other Microsoft services—another entirely normal system behavior.
Bottom line: There's no sign of unauthorized access or intrusion in this output. All connections are tied to trusted, built-in Windows processes doing their regular jobs.
If you still want to double-check:
- You can use the
nslookupcommand (e.g.,nslookup 104.18.35.23) to see exactly which domains those IP addresses belong to—they'll almost certainly be legitimate web services or Microsoft-related hosts. - Run a full system scan with Windows Defender to confirm your system is clean.
备注:内容来源于stack exchange,提问作者Nick Becker
相关产品推荐
相关产品推荐

