Eu duvido que você esteja sendo "hackeado", apenas paranóico. Esses endereços ocorreriam mesmo a partir de uma simples navegação na web, geralmente baseados em websockets. Quebrando cada item na sua lista:
TCP 10.0.0.15:53350 stackoverflow:https ESTABLISHED
TCP 10.0.0.15:54849 stackoverflow:https ESTABLISHED
TCP 10.0.0.15:54960 stackoverflow:https ESTABLISHED
TCP 10.0.0.15:54971 stackoverflow:https ESTABLISHED
Stackoverflow. Likely used to facilitate 'push' notification updates.
TCP 10.0.0.15:53609 msnbot-65-52-108-74:https ESTABLISHED
TCP 10.0.0.15:53598 bay404-m:https ESTABLISHED
TCP 10.0.0.15:53600 65.55.223.31:40001 ESTABLISHED
TCP 10.0.0.15:54139 40.122.209.195:https ESTABLISHED
Microsoft owned. bay404-m Hotmail - Microsoft hosting - Msnbot
TCP 10.0.0.15:53603 91.190.217.45:12350 ESTABLISHED
TCP 10.0.0.15:55714 104.16.125.192:https ESTABLISHED
waves Superuser.com
TCP 10.0.0.15:55757 ec2-23-21-73-17:https CLOSE_WAIT
TCP 10.0.0.15:55905 89-253-65-202:http TIME_WAIT
TCP 10.0.0.15:55908 87-92-39-181:https TIME_WAIT
TCP 10.0.0.15:55913 ip-176-199-254-241:http ESTABLISHED
TCP 10.0.0.15:55914 89-253-65-202:http ESTABLISHED
These ones are harder to work out, one looks like it's related to web chat. Doubtful it's anything malicious.
TCP 127.0.0.1:5354 lmlicenses:49156 ESTABLISHED
TCP 127.0.0.1:5354 lmlicenses:49157 ESTABLISHED
TCP 127.0.0.1:49156 lmlicenses:5354 ESTABLISHED
TCP 127.0.0.1:49157 lmlicenses:5354 ESTABLISHED
TCP [2601:8c:700:86e6:6c23:bd35:ca0:50ef]:55892 lga25s41-in-x0e:https TIM
E_WAIT
TCP [2601:8c:700:86e6:6c23:bd35:ca0:50ef]:55893 lga15s43-in-x0d:https TIM
E_WAIT
TCP [2601:8c:700:86e6:6c23:bd35:ca0:50ef]:55910 iad23s24-in-x0e:https EST
ABLISHED
TCP [2601:8c:700:86e6:6c23:bd35:ca0:50ef]:55911 iad23s43-in-x0d:https EST
ABLISHED
Google - here
Nada na lista é sinistro de alguma forma. Se alguma coisa, minha saída netstat
é provavelmente 4 a 5 vezes mais entradas do que isso.