While monitoring a LAN with Show Traffic, a network monitoring application for Windows systems, I noticed two systems contacting 220.127.116.11 [ 216-115-223-200.expertcity.com ] on port 443 (HTTPS).
Since the communications occurred at 18:30 when the employees using those systems would have gone home, I did a Google search on the FQDN, 216-115-223-200.expertcity.com, which was associated with that address. A McAfee SiteAdvisor webpage linked the site with GoToMeeting, i.e. legitimate software on the users' systems. That webpage stated "When we installed and ran GoToMeeting 18.104.22.168 (gotomeeting.exe), the following network servers were contacted." It then listed the following addresses: