Sponsored

Why is my truck talking to all these IP-addresses?

OP
OP
hb.sagen

hb.sagen

Well-known member
First Name
Henning
Joined
Jul 17, 2025
Threads
18
Messages
140
Reaction score
102
Location
Norway
Vehicles
F150 Lightning 2023 Lariat
Did you filter your pcap capture by the truck's MAC or does your capture include other traffic? I'm not seeing the .mil from my truck in the last 30 days.
Yes, I did filter the capture to my trucks mac. I will recheck the data to be sure.
Sponsored

 
OP
OP
hb.sagen

hb.sagen

Well-known member
First Name
Henning
Joined
Jul 17, 2025
Threads
18
Messages
140
Reaction score
102
Location
Norway
Vehicles
F150 Lightning 2023 Lariat
Yes, I did filter the capture to my trucks mac. I will recheck the data to be sure.
It was a DNS request from my truck to the army address, and it was refused along all the other DNS requests to the root servers. I tries a lot of different root servers, and they all refuse.

And then it uses 1.1.1.1 or dns.google and gets a reply. It even use my default dns resolver from time to time, and gets a response.
 

reddog21

Member
Joined
Jan 17, 2024
Threads
1
Messages
13
Reaction score
5
Location
MA
Vehicles
2023 F150 Lightning Lariat
I did just start capturing traffic from my truck, sendt over wifi. It is talking to a lot of IP-addresses. Some expected, some not so welcome. There are a lot of traffic to the DNS-root servers as well. My plan was to capture a night of traffic, to see if it did anything during nights, as I don't any OTAs. But it went into battery saver mode, even when plugged in, again.

Code:
# Address Name
34.149.193.215 - vehicle.api.mps.ford.com
34.58.221.20 - www.cloud-sync.ford.com
44.239.234.249 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com
52.42.212.232 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com
4.245.95.115 - ford-1-ams.services.tomtom.com
104.19.242.91 - fordoem.gcs.garmin.com
52.42.212.232 - appsvc-ingest.inrix.io
128.63.2.53 - do-not-reuse.arl.army.mil
23.215.0.138 - example.com
There all legitimate, Ford heavily uses aws for cloud api I believe along with google

34.149.193.215 - vehicle.api.mps.ford.com - Cloud communication
34.58.221.20 - www.cloud-sync.ford.com - Sync updates
44.239.234.249 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com - AWS load balancing
52.42.212.232 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com - AWS load balancing
4.245.95.115 - ford-1-ams.services.tomtom.com - Routing
104.19.242.91 - fordoem.gcs.garmin.com - weather/traffic
52.42.212.232 - appsvc-ingest.inrix.io - I believe inrix provides traffic
128.63.2.53 - do-not-reuse.arl.army.mil - It's not an active site it just be from a demo test
23.215.0.138 - example.com - used usually for fallback or test domain
 

thunderbayterry

Well-known member
First Name
Terry
Joined
Dec 22, 2023
Threads
2
Messages
95
Reaction score
123
Location
Thunder Bay, Ontario
Vehicles
2023 F-150 Lightning Lariat ER, 2023 Hummer SUV EV, Mazda MX-30 EV
Occupation
IT
Hey everyone, thank you for this really interesting thread. I'll just contribute a quote I picked up somewhere, from a YouTube EV channel I think: "Remember, your EV is basically a smartphone with wheels" - LOL - I love that!
 

Sponsored

Athrun88

Well-known member
Joined
Sep 30, 2024
Threads
0
Messages
255
Reaction score
291
Location
Toronto, Ontario, Canada
Vehicles
2024 F150 Lightning Lariat ER Avalanche
Hey everyone, thank you for this really interesting thread. I'll just contribute a quote I picked up somewhere, from a YouTube EV channel I think: "Remember, your EV is basically a smartphone with wheels" - LOL - I love that!
Not just EVs; pretty much every new car from 1990 onwards is a computer on wheels to some degree.
 
OP
OP
hb.sagen

hb.sagen

Well-known member
First Name
Henning
Joined
Jul 17, 2025
Threads
18
Messages
140
Reaction score
102
Location
Norway
Vehicles
F150 Lightning 2023 Lariat
This is the list so far, only a few short captures. There is a lot of dns traffic?

Code:
# Address        Name
192.5.6.30        a.gtld-servers.net
192.33.14.30    b.gtld-servers.net
192.26.92.30    c.gtld-servers.net
192.31.80.30    d.gtld-servers.net
192.12.94.30    e.gtld-servers.net
192.35.51.30    f.gtld-servers.net
192.42.93.30    g.gtld-servers.net
192.54.112.30    h.gtld-servers.net
192.43.172.30    i.gtld-servers.net
192.48.79.30    j.gtld-servers.net
192.52.178.30    k.gtld-servers.net
192.41.162.30    l.gtld-servers.net
192.55.83.30    m.gtld-servers.net

198.41.0.4        a.root-servers.net
192.33.4.12        c.root-servers.net
192.203.230.10    e.root-servers.net
192.5.5.241        f.root-servers.net
192.36.148.17    i.root-servers.net
192.58.128.30    j.root-servers.net
193.0.14.129    k.root-servers.net
192.112.36.4    G.ROOT-SERVERS.NET
202.12.27.33    M.ROOT-SERVERS.NET

1.1.1.1            one.one.one.one
8.8.4.4            dns.google
128.63.2.53        do-not-reuse.arl.army.mil

34.149.193.215    vehicle.api.mps.ford.com
34.58.221.20    www.cloud-sync.ford.com

4.245.95.115    ford-1-ams.services.tomtom.com
104.19.242.91    fordoem.gcs.garmin.com

52.42.212.232    appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com
44.239.234.249    appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com

23.220.75.232    example.com

44.239.234.249    appsvc-ingest.inrix.io
52.42.212.232    appsvc-ingest.inrix.io
Sponsored

 
 







Top