Almost Half of Malware Samples Communicate Direct to IP

    Date: 08/05/2026

    Severity: High

    Summary

    The research highlights malware that bypasses traditional DNS-based detection by communicating directly with hardcoded IP addresses instead of resolving domain names. This technique reduces reliance on DNS infrastructure, making network-based monitoring and domain-blocking less effective. SectopRAT, Backdoor and Ransomware droppers, peer-to-peer (P2P) botnets and supply chain risks — communicate directly with hard-coded IP addresses, bypassing DNS entirely and evading DNS-based defenses altogether. 

    Indicators of Compromise (IOC) List

    IP Address

    103.245.236.146

    178.16.54.109

    178.16.54.31

    194.76.227.94

    2.26.98.67

    206.189.229.43

    62.60.179.230

    87.120.107.33

    91.92.243.29

    Hash

    01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2

    9639f7ebc6a6d69d7bf5b8bc869e7783a1406088f192868624ad8919e9bfd1d4

    bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241

    e310476c41ae4f6e3c4ed9bb88303ee6e5e1455bd7afe51cf48965ea7599e6e5

    e3513922666c202c1ae5c06eea277ba10477868d6d89ce2819f4f8ff9070bc85

    e5715e6611ef6bcb233f5d2098510dab3db408abbb728b00e1821bb255829373

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("103.245.236.146","62.60.179.230","178.16.54.31","194.76.227.94","178.16.54.109","2.26.98.67","206.189.229.43","91.92.243.29","87.120.107.33") or srcipaddress IN ("103.245.236.146","62.60.179.230","178.16.54.31","194.76.227.94","178.16.54.109","2.26.98.67","206.189.229.43","91.92.243.29","87.120.107.33")

    Detection Query 2 :

    sha256hash IN ("e310476c41ae4f6e3c4ed9bb88303ee6e5e1455bd7afe51cf48965ea7599e6e5","e5715e6611ef6bcb233f5d2098510dab3db408abbb728b00e1821bb255829373","9639f7ebc6a6d69d7bf5b8bc869e7783a1406088f192868624ad8919e9bfd1d4","bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241","01a96eeafb72042b3f69afd21b4c9155dbfe7f97ab3dca392972ad531a075ac2","e3513922666c202c1ae5c06eea277ba10477868d6d89ce2819f4f8ff9070bc85")

    Reference: 

    https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/       


    Tags

    MalwareRansomwareBotnetSupply chain attackRATBackdoor

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags