Excessive data use on my internet plan and troubleshooting question
Like many others, I've been struggling to figure out why my data consumption has jumped drastically from December to January.
I've done the following so far and have found an IP Address that seems to be consuming a lot of data.
- Changed my Wifi passwords
- Identified all IP addresses using my router
- Turned off all IP addresses to see if data consumption reduced remarkably - it did indeed drop the day to day usage immediately (observed over night)
- Turned some IP addresses back on and correlated increase in data consumption as devices were turned back on (observed over the period of several days)
- Lodged a request to my ISP - multiple phone calls and Chat Agent interactions so far, assuring me they're investigating and will call me back but nobody has yet; confirmed in writing to me that I will not suffer a charge associated with any overage while under investigation
- Consulted the Apple Community to see what resolved others' concerns - haven't seen anything yet that definitively resolved the issue but got ideas
- Investigated MoCA - still on my list of possible things to try (not itching to spend any money to fix an issue I don't know root cause yet)
- Investigated IP traffic monitoring apps and ended up downloading Wireshark - learned Wireshark over the past couple days
- Created pcap files and used Statistics feature of Wireshark to look at all IP addresses on my network to see if any stood out as having a large amount of chatter on them
- Used filter to watch any conversation on the network which had a specific IP address of interest and traced that conversation to my main iMac device which I'm using currently with Wireshark
- Noticed an IP address that had the absolute highest amount of total packets of 114,690 over 4.5 minutes
- Total data from A->B was 115 MB over 4.5 minutes (the external IP address to my computer)
- The IP address in question is 17.248.190.140 which I used an IP WHOIS lookup web site and tracked it down to an Apple owned IP but I don't know what it does and that's where my trail ended
- All other devices are quiet with one exception. I saw a very small amount of communication within my own network from an AppleTV device to my main computer
- I grabbed a 2nd pcap to confirm I'm still seeing the same level of traffic coming from 17.248.190.140 and it is indeed, still happening.
I know it's not definitive but I think I could be onto something. It seems interesting to me that 115MB of data was sent to my machine in a 4.5 minute data log while I was using Wireshark trying to figure out what's happening.
Worth noting is that on 1/4/24, I turned in all my Comcast equipment for the TVs in our home and had Comcast TV turned OFF. I also added YouTube TV on 1/5/24 but we haven't spent much time on that app through any of our TVs. I went so far as to log into YouTube TV on each device, then exit the apps (but not log out) like we do all streaming apps on AppleTV devices and iPhones or iPads.
Also worth noting is that I've increased our data speed from 800 GB/s to 1000 GB/s also on 1/5/24. Data cap is 1.2TB for each month (1/1/24 through 1/31/24 I believe - Comcast measures upload/download data for any given month which is asynchronous with their billing cycle).
Does anyonoe have any ideas where I go from here and if I'm on the right trail with what I've done so far? Comcast has been completely useless, not to mention terribly frustrating. I don't know what that IP address is that I mentioned above but it's something to do with Apple. It seems to be a high amount of data being used in the background and if this is something always happening on my computer, surely that would add up fast. For example, 60 minutes in 1 hr so 60/4.5 =13.3333 pcap measurement intervals in an hour. 115 MB X 13.33333 = 1.533 GB/hr of data consumption. Multiply that by 24 hours in a full day and I get 36.8GB. My average daily consumption this month is around 50 GB/day with only a few hours of Netflix in the evenings. Prior consumption per day was about 1/2 to 1/3 what it has been this month.
Could it be this one IP address causing me all this grief and coming from an Apple IP address?
This issue began as far as I can tell, as soon as January started but BEFORE I turned in equipment to Comcast as far as I can recall but I didn't take any screenshots of data utilization before I turned in equipment.
I'm running an antivirus program, always, and periodically use VPN which comes with the SaaS subscription I signed up for a few years ago which I'm very happy with.
I'm desperate for help!
2nd pcap, Statistics, Communication... Longer period of time for this capture but it looks like 124MB in this case and 115MB in the above case. Something's happening and I don't know what it is or how to stop it. HELP! TIA!
UPDATE: Looks like that IP Address is an Apple Data Center.
iMac (2017 – 2020)