Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Almost Half of Malware Samples Communicate Direct to IP

0
Medium
Published: 08/04/2026 (08/04/2026, 13:08:10 UTC)
Source: AlienVault OTX General

Description

Analysis of 4 million dynamic malware reports shows that nearly half of malware samples with command-and-control (C2) activity use direct-to-IP (D2IP) connections, bypassing DNS and evading DNS-based defenses. D2IP accounts for over 23% of all C2 attempts and is observed in diverse malware families including ransomware droppers, data exfiltration campaigns, and IoT botnets. The research proposes a zero trust IP (ZT-IP) enforcement approach to block unauthorized outbound IP connections that are not sanctioned by DNS responses.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 15:32:20 UTC

Technical Analysis

This research analyzes 4 million dynamic malware reports and finds that 45.32% of malware samples exhibiting command-and-control activity establish direct-to-IP (D2IP) connections, completely bypassing DNS resolution. This evasion technique undermines traditional DNS-based security controls. D2IP traffic constitutes 23.17% of all C2 connection attempts. The behavior is present across multiple malware types such as Phorpiex ransomware droppers with hard-coded IPs, persistent data exfiltration campaigns using obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating via peer-to-peer networks. The study introduces zero trust IP (ZT-IP), a network-level enforcement mechanism that validates outbound connection destinations against previously authorized DNS responses to block malicious D2IP communications.

Potential Impact

Malware using direct-to-IP connections can evade DNS-based detection and blocking mechanisms, increasing the difficulty of identifying and mitigating command-and-control communications. This technique enables persistent and stealthy malware operations including ransomware deployment, data exfiltration, and botnet propagation. The widespread use of D2IP across diverse malware families and attack vectors highlights a significant gap in traditional network security defenses relying on DNS monitoring.

Defensive Guidance

No official patch or vendor advisory is available for this behavior as it is a malware communication technique rather than a software vulnerability. The research proposes implementing zero trust IP (ZT-IP) network enforcement, which restricts outbound connections to IP addresses previously authorized by DNS responses. Organizations should consider deploying network-level controls that verify IP destinations against DNS resolutions to detect and block unauthorized direct-to-IP communications. This approach complements existing DNS-based security controls and addresses the evasion technique described.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"]
Adversary
null
Pulse Id
6a71e43a0127c62218b7c365
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip103.245.236.146
ip154.92.19.71
ip178.16.54.109
ip91.92.243.29
ip194.76.227.94
ip178.16.54.31
ip87.120.107.33
ip2.26.98.67
ip62.60.179.230

Hash

ValueDescriptionCopy
hash083d5895283755a910b5c59d60a5348b
hash0d94bf4d0418061907ff7977e3f25a463cb25188
hash9639f7ebc6a6d69d7bf5b8bc869e7783a1406088f192868624ad8919e9bfd1d4
hashe3513922666c202c1ae5c06eea277ba10477868d6d89ce2819f4f8ff9070bc85
hash01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2
hashbf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241
hash946a9cc6b501d993a108c90ef7d0930d
hashc98aa812a271c9c78017c2c90b60a97ae13df9cf
hash04d20417bb04779c8762032b8c6942be
hash0783237785d65621d1e887f24cc2103b
hash1fec4103f40b6432e45d67fc87b504e024962376
hash7f6f4b3b341818b6db89fac39efb6c257addde95
hashcc43cdbe8eb9874f55fffbe23b560b673eb9f31fb9a953926bba29464fd2dd07
hashe310476c41ae4f6e3c4ed9bb88303ee6e5e1455bd7afe51cf48965ea7599e6e5
hashe5715e6611ef6bcb233f5d2098510dab3db408abbb728b00e1821bb255829373

Threat ID: 6a71fa1ebf8831d539f4fa54

Added to database: 08/04/2026, 14:41:34 UTC

Last enriched: 08/04/2026, 15:32:20 UTC

Last updated: 08/04/2026, 18:31:39 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses