Sponsored

Why is my truck talking to all these IP-addresses?

hb.sagen

Well-known member
First Name
Henning
Joined
Jul 17, 2025
Threads
18
Messages
136
Reaction score
99
Location
Norway
Vehicles
F150 Lightning 2023 Lariat
I did just start capturing traffic from my truck, sendt over wifi. It is talking to a lot of IP-addresses. Some expected, some not so welcome. There are a lot of traffic to the DNS-root servers as well. My plan was to capture a night of traffic, to see if it did anything during nights, as I don't any OTAs. But it went into battery saver mode, even when plugged in, again.

Code:
# Address Name
34.149.193.215 - vehicle.api.mps.ford.com
34.58.221.20 - www.cloud-sync.ford.com
44.239.234.249 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com
52.42.212.232 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com
4.245.95.115 - ford-1-ams.services.tomtom.com
104.19.242.91 - fordoem.gcs.garmin.com
52.42.212.232 - appsvc-ingest.inrix.io
128.63.2.53 - do-not-reuse.arl.army.mil
23.215.0.138 - example.com
Sponsored

 

rugedraw

Well-known member
First Name
Javier
Joined
Dec 14, 2021
Threads
4
Messages
1,767
Reaction score
2,115
Location
Miami
Vehicles
2021 Ford F150 Platinum FX4 EB/2023 Bronco Sport Badlands/1991 Mustang 5.0 coupe
Occupation
Auto Sales
128.63.2.53 - do-not-reuse.arl.army.mil
I don't have the answer to your question, but this one is registered to the US Department of War.

Break out your tin foil hats!!!!!
 

GDN

Well-known member
First Name
Greg
Joined
Feb 15, 2022
Threads
94
Messages
3,727
Reaction score
4,753
Location
Dallas, TX
Vehicles
Lightning Lariat ER, Performance Y
Occupation
IT
I don't have the answer to your question, but this one is registered to the US Department of War.

Break out your tin foil hats!!!!!
Maybe something to do with GPS?

Working with @bmwhitetx on reviewing some map differences, I found this yesterday. The Navigation has to know data about the GPS satellites - and Russia's too I guess - Glonass.
Ford F-150 Lightning Why is my truck talking to all these IP-addresses? IMG_9798


PS - I'll save you some time with those coordinates. They might give away my neighborhood, but my profile already says Dallas. Those coordinates will take you to lunch at Panda Express.
 

chriserx

Well-known member
First Name
Chris
Joined
Oct 3, 2025
Threads
1
Messages
163
Reaction score
95
Location
Louisiana
Vehicles
2025 Ford Lightning Flash Job 2 😭
I did just start capturing traffic from my truck, sendt over wifi. It is talking to a lot of IP-addresses. Some expected, some not so welcome. There are a lot of traffic to the DNS-root servers as well. My plan was to capture a night of traffic, to see if it did anything during nights, as I don't any OTAs. But it went into battery saver mode, even when plugged in, again.

Code:
# Address Name
34.149.193.215 - vehicle.api.mps.ford.com
34.58.221.20 - www.cloud-sync.ford.com
44.239.234.249 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com
52.42.212.232 - appsvc-dataingest-844929136.us-west-2.elb.amazonaws.com
4.245.95.115 - ford-1-ams.services.tomtom.com
104.19.242.91 - fordoem.gcs.garmin.com
52.42.212.232 - appsvc-ingest.inrix.io
128.63.2.53 - do-not-reuse.arl.army.mil
23.215.0.138 - example.com
Best guesses:
1) Ford app API polling instead of push
2) Vehicle status
3 & 4) Alexa/Amazon services
5 & 6) GPS traffic/routing/elevation, possibly weather
7) Vehicle usage analytics
8) ARP, reverse domain lookup
9) Shot in the dark here without port testing but possibly is online/offline status

Edit: Just read the rest of the thread, yeah kinda crazy to see the US military being contacted until you realize the modern internet was born out of ARPANET. Also, it's possible that it's being used as an authoritative DNS server, not at my computer to attempt a port scan.
 
Last edited:

Sponsored

carys98

Well-known member
First Name
Cary
Joined
Jan 15, 2022
Threads
29
Messages
785
Reaction score
1,195
Location
Raleigh, NC
Vehicles
2023 Lightning Lariat SR
Occupation
Retired EE
Best guesses:
1) Ford app API polling instead of push
2) Vehicle status
3 & 4) Alexa/Amazon services
5 & 6) GPS traffic/routing/elevation, possibly weather
7) Vehicle usage analytics
8) ARP, reverse domain lookup
9) Shot in the dark here without port testing but possibly is online/offline status
3 and 4 could still be Ford renting AWS space to store data.
 

chriserx

Well-known member
First Name
Chris
Joined
Oct 3, 2025
Threads
1
Messages
163
Reaction score
95
Location
Louisiana
Vehicles
2025 Ford Lightning Flash Job 2 😭
3 and 4 could still be Ford renting AWS space to store data.
Definitely could be, I only ruled it out because of number 2, and the appsvc subdomain in 3 & 4. I'm at work now so I'm left to speculation instead of testing 😢

Edit: I had actually been wanting to do this for a while, so thanks for doing it for me. I'd love to send all of the cellular through my personal VPN to analyze all of the traffic but the modem is pretty locked down. :(
 
Last edited:

Sponsored

sysop1

Active member
Joined
Aug 2, 2022
Threads
2
Messages
37
Reaction score
53
Location
St.George
Vehicles
Gas
Did you filter your pcap capture by the truck's MAC or does your capture include other traffic? I'm not seeing the .mil from my truck in the last 30 days.
 

tls

Well-known member
Joined
Apr 29, 2022
Threads
22
Messages
495
Reaction score
475
Location
New York
Vehicles
2022 Lightning
That address at ARL is one of the original root DNS servers. It's been renamed to "do-not-reuse" to remind ARL staff that it's now unusable for any other purpose because ancient software like the version of QNX in our trucks bombards it with literally billions of DNS queries per minute even though it has not been a root server for a decade.
 
  • Sad
Reactions: GDN

sysop1

Active member
Joined
Aug 2, 2022
Threads
2
Messages
37
Reaction score
53
Location
St.George
Vehicles
Gas
That address at ARL is one of the original root DNS servers. It's been renamed to "do-not-reuse" to remind ARL staff that it's now unusable for any other purpose because ancient software like the version of QNX in our trucks bombards it with literally billions of DNS queries per minute even though it has not been a root server for a decade.
I only have 30 days of data but I don't see that IP from my truck.
 

GDN

Well-known member
First Name
Greg
Joined
Feb 15, 2022
Threads
94
Messages
3,727
Reaction score
4,753
Location
Dallas, TX
Vehicles
Lightning Lariat ER, Performance Y
Occupation
IT
Do we get a free lunch if we mention your name ?
Definitely off topic, but I eat there probably once a week for lunch and after a couple of years not one employee has ever acted like they remember who I am. Have the super greens, Teriyaki chicken without the sauce and Kung Pao chicken - somewhat healthier than a burger and fries.
Sponsored

 
 







Top