Unexpectedly, after updating KeePassXC started knocking on the Internet. Is this behavior normal?

windows10 keepassxc.exe, ‎11.‎03.‎2024 ‏‎18:40:26, 52509, 140.82.121.5, lb-140-82-121-5-fra.github.com, 443 (https), tcp, Outbound, [B] Internal\BlockConnection

27 points · 12 comments · view on lemmy.world

12 Comments

LWD@lemm.ee · 13 pts · 2y
[ removed ]
Gooey0210@sh.itjust.works · 11 pts · 2y

Maybe it's trying to get favicons?

UID_Zero@infosec.pub · 8 pts · 2y (2 replies)

Is that it's update check?

Garrytianomorph@lemmy.world · 4 pts · 2y

it's disabled

itsnotits@lemmy.world · 3 pts · 2y

its* update check

Matt@lemdro.id · 6 pts · 2y (1 reply)

There is a setting to automatically check for updates. I would see if that is enabled.

Garrytianomorph@lemmy.world · 4 pts · 2y

keepassxc is blocked by the firewall and updates are disabled, so calling the firewall confused me

Turbo@lemmy.ml · 5 pts · 2y (2 replies)

Did you get the app from trusted source? Did you check the md5 / sha512 hash after downloading to ensure no tamper?

That would freak me out also..

fizzyvelcro@lemmy.world · 1 pts · 2y (1 reply)

Checking the hash is only useful to confirm a correct download. If someone can change what binary you download, they can also change the hash and would be stupid not to…

Turbo@lemmy.ml · 1 pts · 2y

Forsure, but if you still had the download and went to the sites official page today and could check if it matches to alleviate fear you downloaded a fake version etc.

Squire1039@lemm.ee · 5 pts · 2y (2 replies)

VirusTotal doesn't indicate keepassxc.exe 2.7.7 contacts this address. I'd be careful. Check the binaries' signatures. Try a full install to see if that behaves differently.

keppassxc.exe: https://www.virustotal.com/gui/file/fea4df5024f83155f6742a3372a801fc6cc97ed82627b36fce6f0caed54506cf/relations

KeePassXC-2.7.7-Win64.msi: https://www.virustotal.com/gui/file/9c3dab957db0f769c4e67bfdf4f0134a65ecfa65c5569718a36aa88e649158cd

Garrytianomorph@lemmy.world · 3 pts · 2y (1 reply)
Squire1039@lemm.ee · 3 pts · 2y

140.82.121.5

Well, apparently, this is an A record for api.github.com. This name resolves to a different IP around the globe. See https://www.whatsmydns.net/#A/api.github.com

The IP is detected as "clean" on VirusTotal: https://www.virustotal.com/gui/ip-address/140.82.121.5/detection , although apparently (probably not surprising as it is github) is also a favorite address for everything including malware.

Maybe you can ask in the keepassxc discussion forum on github.