Apps connecting to remote torrent tracker

For some weird reason, Adobe Reader, SpiderOak, Firefox, and other Internet-aware apps are trying to connect what seems to be some sort of torrent trackers. I managed to find it in Online Armor logs. I'm baffled that all point to localhost address plus some random port.








Could it be some backdoor going through?

There's a couple of other threads that mention the same issue (with different domains).




From what I can tell (and have occasionally observed myself), it seems like the domain on an initial popup is remembered and then shows up again on subsequent popups even though the current connection is unrelated to that domain. People report that the problem usually resolves itself at some point, though it may reoccur.

Thanks for the tip!

Still I'm wondering for all the domains available, why a torrent tracker I've never seen before?. :wacko:

I just started to get similar connection alerts,and I have never used any torrent trackers.

I may have visited the page at once, but never downloaded anything from it whatsoever.

Hello everyone,

As you can see from the posted logs, the connections are being made to the localhost (

The connections are not being made to any torrent trackers.

Just a note:

It's not a rare occasion when some domains are being blocked (NOT by Online Armor) by returning ip address in dns reply.

Online Armor just intercepts dns replies to show additional information in the popups.

