by Fantius on Mon Dec 04, 2006 4:48 pm
lackattack,
Obviously you are right to not trust any old exe that you download. The program does not talk to any host other than the one you tell it to check.
The IP that you cited is owned by the hosting company that is hosting the exe. Is it possible that you still had the browser opened that you downloaded though and it was still communicating? That's the only explanation that I can think of.
Actually, I did have another paranoid thought: What if the hosting company altered the exe on it's own? To test this, I donloaded the exe from paulcrowder.net, installed and started WireShark (packet sniffer), and then ran the exe. I only saw it communicate with conquerclub's IP and my router.
If there is some better way I can check this, please let me know. Or if anyone else has checked this, please let us know your results. I certainly don't want my program doing something that I didn't tell it to do and don't want it doing.