Please offer opinion on data drain, documented by Glasswire
This is very strange with an unfortunately long and tedious report. I've really never seen anything like this over my time with Hughes beginning in 2011. I'm trying to understand what happened with an absurd amount of data loss that began sometime Friday Sept 1. This happened exclusively on my ethernet connected main computer. I just found it this morning. I only discovered it because my service plan rolls over tomorrow night. I wanted to set up an hourly testmy routine to run until then to see how poorly my Gen 5 service is doing this month. It appears whatever this thing is, ran until it consumed all of my monthly service plan allowance and then became disinterested.
For Friday, Glasswire says Google Chrome used 4.0 GB download out of a total 4.5 GB WAN. These 4 GB show up as going to IP 2a03:2880:f082:112:face:b00c:0:1823
For Saturday, Google Chrome used 5.4 GB of the 6.1 GB total WAN. 4.9 GB shows going to the same IP 2a03:2880:f082:112:face:b00c:0:1823
Chrome typically uses 15-50 MB per day. There isn't a lot I use it for. I did use it for hours Saturday afternoon to work on a complicated google docs investment spreadsheet using source data read in Vivaldi but the drain started the day before so it can't be related. Typically, my main and most regular usage for Chrome is leaving my Hughesnet SCC page open forever and sifting junk/reporting phishing mail at the live.com web interface for my outlook email accounts used by Thunderbird. Otherwise it's only used for managing my Google Merchant accounts and other Google services and the occasional search using Startpage.
Looking up the plain English iteration of the offending IP 2a03:2880:f082:112:face:b00c:0:1823
reveals it's edge-video6-shv-02-ord5.fbcdn.net.
I can't find any of this in any of the Glasswire history prior to Friday. Going to the plain English iteration of the IP reveals it's a stinkin facebook page that says:
-------------------------------------------------------------
Sorry, something went wrong.
We're working on it and we'll get it fixed as soon as we can.
Using that "Go Back" link takes me to a facebook log in page.
Funny since I do not use facebook. The only time I ever open a facebook page is within an isolated Firefox Facebook Container tab. I do have a couple of old fake facebook accounts. I can't remember the last time I logged in with one and would never use something like Chrome for that.
A very odd thing is this facebook page is only accessible when connected through Hughesnet,
When connected by Verizon I can only get this in Firefox "Hmm. We’re having trouble finding that site. We can’t connect to the server at edge-video6-shv-02-ord5.fbcdn.net.
The exact same thing happens when accessing this address from one of my wifi connected windows computers. I can see it when connected by Hughesnet but not when connected by Verizon. Even worse, the exact same thing happens when using my android phone. All this makes it appear it's all something to do with the Hughes network.
The Glasswire log for 8 am shows only 107.9 MB went to this same IP 2a03:2880:f082:112:face:b00c:0:1823 today but that hasn't increased since I discovered it when I woke the computer up at 5:30 this morning to do some work.
I left everything going as is until 8 am when I disabled the ethernet supplying the Hughesnet and reconnected by alternate ethernet using Verizon. The drain to 2a03:2880:f082:112:face:b00c:0:1823 for today hasn't increased so maybe it's over.
The computer is clean. A Bitdefender scan of the C: drive shows absolutely nothing. Chrome did get an update Thursday afternoon but I don't see how that could have set something off to start running Friday.
Any thoughts? Thanks!