My iPhone is receiving unwanted connection attempts from known TOR router addresses
My home network firewall has been flagging (and blocking) inbound connection attempts from known TOR routers in various countries (Iceland, Switzerland, Hungary). The implication is that an app on my phone is forwarding my WiFi IP address and a port to a C&C somewhere; the source IP of that communication will tell the C&C my home ISP address and then an attempt is made to forward through my ISP to the internal IP address. While I trust iOS sandboxing and my home network firewall, I have no idea what happens when I connect over cellular or a public WiFI hotspot. In any case, the idea that I have an app trying to enable connections back from TOR routers makes me uneasy.
I've run a port scan on my phone and found a handful of open ports - eg:
Not shown: 65531 closed tcp ports (conn-refused)
PORT STATE SERVICE
853/tcp open domain-s
50592/tcp filtered unknown
56595/tcp open unknown
62078/tcp open iphone-sync
But I don't know how to correlate these with any specific app. Does anyone have any tips for doing so? Otherwise I'll methodically go through all apps that are running at the time of these alerts and uninstall them until the problem (alerts from my firewall and/or open ports on my phone) goes away. I could just reset the whole phone but I'd like to have some idea of what app is doing this so I can report them.
iPhone 14 Pro Max, iOS 18