- Nov 12, 2023
- 1
Need help interpreting Firewall AI logs.
Can the fact that almost all network connections made by apps on a phone also have duplicates with an Unknown Process initiating them, be a sign of stalkerware?
I'm using Firewall AI's log. One phone has this for every connection (Samsung Galaxy A6, Android 11), the other almost doesn't (A13, Android 13), except Google Play Services.
What I see is a legit app, marked by its icon, making a connection to x and above it an UnknownProcess , marked by android's "half-face" icon, making the same connection at the same time xx.xx.xx.
Also, if I block a connection by an UnknownProcess, the corresponding connection made by a legit app gets blocked too, but I'm assuming it's because the destination is the same(?).
Otherwise most popular AVs detected nothing, except AntiSpy marked a dsms from a samsung package as a threat (Trojan)...
PyDroid logs detect the same duplicate connections, only it attributes both to the app making the connection.
My phone was meddeled with a year ago (stolen for 1 day).
Can the fact that almost all network connections made by apps on a phone also have duplicates with an Unknown Process initiating them, be a sign of stalkerware?
I'm using Firewall AI's log. One phone has this for every connection (Samsung Galaxy A6, Android 11), the other almost doesn't (A13, Android 13), except Google Play Services.
What I see is a legit app, marked by its icon, making a connection to x and above it an UnknownProcess , marked by android's "half-face" icon, making the same connection at the same time xx.xx.xx.
Also, if I block a connection by an UnknownProcess, the corresponding connection made by a legit app gets blocked too, but I'm assuming it's because the destination is the same(?).
Otherwise most popular AVs detected nothing, except AntiSpy marked a dsms from a samsung package as a threat (Trojan)...
PyDroid logs detect the same duplicate connections, only it attributes both to the app making the connection.
My phone was meddeled with a year ago (stolen for 1 day).