unit42 · Crawled Aug 4, 2026
Almost Half of Malware Samples Communicate Direct to IP
22 IoCs 3 Malware
Read original article ↗
AI Summary
A significant portion of malware samples bypass DNS by communicating directly to IP addresses, evading DNS-based security controls. Analysis of 4 million dynamic reports shows 45.32% of malware with command-and-control (C2) activity used direct-to-IP (D2IP) connections, accounting for 23.17% of all C2 attempts. Threats identified include Phorpiex ransomware droppers, a data exfiltration campaign using obfuscated \GET requests, SectopRAT deployments targeting educational institutions, and IoT botnets like Mozi and a new Mirai variant named Boatnet. These threats leverage hard-coded IP addresses and custom HTTP methods to avoid detection and maintain persistence.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 22 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 154[.]92[.]19[.]71 | Details → |
| IP | 178[.]16[.]54[.]109 | Details → |
| IP | 18[.]228[.]188[.]56 | Details → |
| IP | 87[.]120[.]107[.]33 | Details → |
| IP | 194[.]76[.]227[.]94 | Details → |
| IP | 2[.]26[.]98[.]67 | Details → |
| IP | 62[.]60[.]179[.]230 | Details → |
| IP | 91[.]92[.]243[.]29 | Details → |
| IP | 103[.]245[.]236[.]146 | Details → |
| IP | 178[.]16[.]54[.]31 | Details → |
| IP | 206[.]189[.]229[.]43 | Details → |
| Filename | st.exe | Details → |
| Filename | /hiddenbin/ | Details → |
| Filename | /churl | Details → |
| Filename | /fsave | Details → |
| SHA-256 | cc43cdbe8eb9874f55fffbe23b560b673eb9f31fb9a953926bba29464fd2dd07 | Details → |
| SHA-256 | 01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2 | Details → |
| SHA-256 | 9639f7ebc6a6d69d7bf5b8bc869e7783a1406088f192868624ad8919e9bfd1d4 | Details → |
| SHA-256 | bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241 | Details → |
| SHA-256 | e310476c41ae4f6e3c4ed9bb88303ee6e5e1455bd7afe51cf48965ea7599e6e5 | Details → |
| SHA-256 | e3513922666c202c1ae5c06eea277ba10477868d6d89ce2819f4f8ff9070bc85 | Details → |
| SHA-256 | e5715e6611ef6bcb233f5d2098510dab3db408abbb728b00e1821bb255829373 | Details → |
MITRE ATT&CK TTPs 17 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1059 Command and Scripting Interpreter · Execution T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1001.003 Protocol or Service Impersonation · Command And Control T1014 Rootkit · Defense Evasion T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1497 Virtualization/Sandbox Evasion · Defense Evasion T1539 Steal Web Session Cookie · Credential Access T1555 Credentials from Password Stores · Credential Access