FWIW,
In the two hour capture session from my perimeter firewall I only captured IRC traffic to three different hosts
In quick succession at launching Invision I had two failed connection attempts, the first to a definite Austnet server (to which network I was wanting to connect) led to a series of SYN / RESET pairs until it went on to the next server which I can't confirm is Austnet's but IS an Australian host (the IP was 203.89.209.20) this was a short sequence of unresponded SYNs and then finally the establishment of the connection with the server I remain connected to.
Just out of curiosity, I ran an ngrep on the capture file for any occurrence of a channel name starting with N (both cases) and found nothing.
Your point is well taken, however, that there may be an odd trojanized version distributed from a non-official mirror. I just wanted to test my setup as I do get those apparent "trojan" alerts on this version. I never saw any strange activity from my laptop but thought I would put it through a more formal test
Regards,
Piers