unit42 · Crawled Aug 4, 2026

Almost Half of Malware Samples Communicate Direct to IP

22 IoCs 3 Malware
Read original article ↗

AI Summary

A significant portion of malware samples bypass DNS by communicating directly to IP addresses, evading DNS-based security controls. Analysis of 4 million dynamic reports shows 45.32% of malware with command-and-control (C2) activity used direct-to-IP (D2IP) connections, accounting for 23.17% of all C2 attempts. Threats identified include Phorpiex ransomware droppers, a data exfiltration campaign using obfuscated \GET requests, SectopRAT deployments targeting educational institutions, and IoT botnets like Mozi and a new Mirai variant named Boatnet. These threats leverage hard-coded IP addresses and custom HTTP methods to avoid detection and maintain persistence.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 22 extracted

Type Value Detail
IP 154[.]92[.]19[.]71 Details →
IP 178[.]16[.]54[.]109 Details →
IP 18[.]228[.]188[.]56 Details →
IP 87[.]120[.]107[.]33 Details →
IP 194[.]76[.]227[.]94 Details →
IP 2[.]26[.]98[.]67 Details →
IP 62[.]60[.]179[.]230 Details →
IP 91[.]92[.]243[.]29 Details →
IP 103[.]245[.]236[.]146 Details →
IP 178[.]16[.]54[.]31 Details →
IP 206[.]189[.]229[.]43 Details →
Filename st.exe Details →
Filename /hiddenbin/ Details →
Filename /churl Details →
Filename /fsave Details →
SHA-256 cc43cdbe8eb9874f55fffbe23b560b673eb9f31fb9a953926bba29464fd2dd07 Details →
SHA-256 01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2 Details →
SHA-256 9639f7ebc6a6d69d7bf5b8bc869e7783a1406088f192868624ad8919e9bfd1d4 Details →
SHA-256 bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241 Details →
SHA-256 e310476c41ae4f6e3c4ed9bb88303ee6e5e1455bd7afe51cf48965ea7599e6e5 Details →
SHA-256 e3513922666c202c1ae5c06eea277ba10477868d6d89ce2819f4f8ff9070bc85 Details →
SHA-256 e5715e6611ef6bcb233f5d2098510dab3db408abbb728b00e1821bb255829373 Details →

MITRE ATT&CK TTPs 17 techniques