Rapportd process tries to connect to hundreds of IP addresses - what is going on?

Hi,

recently my Little Snitch firewall has detected the process rapportd trying to connect or receive connection from multiple IPs (like 200 + of them) from all around the world, including Russia, China and Pakistan.

Can anybody comment on what is going on?

MacBook Pro 15", macOS 10.14

Posted on Jul 6, 2019 6:54 AM

Reply
7 replies

Jul 6, 2019 7:53 AM in response to Alex Shum

Apple has a daemon that manages Handoff (part of Continuity).

There is also a IBM "security" piece of garbage that Banks push customers to install. It is called Trusteer Rapport.

It also runs a daemon called rapportd. It runs from this path: /Library/Rapport/bin/rapportd.app/Contents/MacOS/rapportd

So, if you can tell where the daemon is running from, you might be able to tell them apart.


Here is the Man page for Apple's rapportd:

rapportd(8)               BSD System Manager's Manual              rapportd(8)

NAME
     rapportd -- Rapport Daemon.

SYNOPSIS
     Daemon that enables Phone Call Handoff and other communication features
     between Apple devices.

     Use '/usr/libexec/rapportd -V' to get the version.

LOCATION
     /usr/libexec/rapportd

Jul 6, 2019 3:39 PM in response to Alex Shum

I never use any third party security apps on my macs.
Little Snitch firewall has detected

Those two sentences are orthogonal and do not intersect.


I don't know why yours is contacting all of those servers. Having it on most of the day, mine has only sent 2kB of data (23 packets).

Perhaps your "not third party security app" is not functioning properly.

Jul 7, 2019 1:07 AM in response to Barney-15E

Yeah, I kind of got so much used to little snitch that I forgot it falls under the category.

So, you idea is that it is the Little Snitch itself that uses the rapportd to connect to hundreds of IPs? I find that very doubtful.

I will continue investigating, and as a last resort I have already downloaded the Mojave install app. I guess maybe its time for full erase and reinstall....

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Rapportd process tries to connect to hundreds of IP addresses - what is going on?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.