You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于netstat -b输出的网络连接是否存在入侵风险的咨询

关于netstat -b输出的网络连接是否存在入侵风险的咨询

Hey there, let's walk through your netstat -b output step by step to put your mind at ease:

First, here's the output you shared for reference:

C:\Windows\system32>netstat -b

Active Connections

  Proto  Local Address          Foreign Address        State
  TCP    192.168.4.131:49670    104.18.35.23:https     ESTABLISHED
 [msedge.exe]
  TCP    192.168.4.131:49780    47:https               ESTABLISHED
 [msedge.exe]
  TCP    192.168.4.131:50226    104.18.40.222:https    TIME_WAIT
  TCP    192.168.4.131:50286    160:https              ESTABLISHED
 [msedge.exe]
  TCP    192.168.4.131:50635    13.69.239.74:https     ESTABLISHED
 [msedge.exe]
  TCP    192.168.4.131:50986    104.18.35.23:https     ESTABLISHED
 [msedge.exe]
  TCP    192.168.4.131:51013    a23-63-180-17:https    ESTABLISHED
 [msedge.exe]
  TCP    192.168.4.131:51965    104.18.41.33:https     TIME_WAIT
  TCP    192.168.4.131:52513    52.238.235.86:https    CLOSE_WAIT
 [SystemSettings.exe]
  TCP    192.168.4.131:53543    101:https          ...

Now, let's break down what this means:

  • Most active connections are from msedge.exe: This is your Microsoft Edge browser, and these connections are completely normal. Every time you open a website, load images, sync browser data, or even have tabs running in the background, Edge establishes HTTPS connections to web servers. The incomplete foreign addresses (like 47:https or 160:https) are just temporary DNS resolution glitches—nothing to worry about, since the process is still your legitimate browser.
  • TIME_WAIT state connections: These are connections that have recently closed. The TIME_WAIT state is a standard part of TCP's connection cleanup process, ensuring all data is fully transmitted before the connection is fully terminated. No red flags here.
  • CLOSE_WAIT connection from SystemSettings.exe: This is Windows' System Settings app. It likely established this connection to check for system updates, sync your Microsoft account settings, or access other Microsoft services—another entirely normal system behavior.

Bottom line: There's no sign of unauthorized access or intrusion in this output. All connections are tied to trusted, built-in Windows processes doing their regular jobs.

If you still want to double-check:

  • You can use the nslookup command (e.g., nslookup 104.18.35.23) to see exactly which domains those IP addresses belong to—they'll almost certainly be legitimate web services or Microsoft-related hosts.
  • Run a full system scan with Windows Defender to confirm your system is clean.

备注:内容来源于stack exchange,提问作者Nick Becker

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.16 11:38:03