This detection identifies adversary activity by matching network and endpoint telemetry against nine specific Indicators of Compromise (IOCs) linked to the Mozi threat actor, enabling the identification of potential early-stage intrusions or lateral movement. A proactive hunt is essential in Azure Sentinel because Mozi’s sophisticated tradecraft often involves stealthy initial access that may evade standard automated alerts, requiring manual correlation to prevent undetected persistence and data exfiltration.
Malware Family: Mozi Total IOCs: 9 IOC Types: url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxp://190[.]196[.]253[.]119:10701/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://223[.]123[.]44[.]122:42812/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://103[.]176[.]16[.]59:34532/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://116[.]140[.]6[.]114:46743/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://103[.]225[.]191[.]202:34773/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://153[.]117[.]40[.]170:44217/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://110[.]186[.]229[.]108:47843/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://115[.]57[.]182[.]131:41041/Mozi.m | payload_delivery | 2026-08-20 | 75% |
| url | hxxp://183[.]63[.]8[.]194:46154/Mozi.m | payload_delivery | 2026-08-20 | 75% |
// Hunt for access to known malicious URLs
// Source: ThreatFox - Mozi
let malicious_urls = dynamic(["http://190.196.253.119:10701/Mozi.m", "http://223.123.44.122:42812/Mozi.m", "http://103.176.16.59:34532/Mozi.m", "http://116.140.6.114:46743/Mozi.m", "http://103.225.191.202:34773/Mozi.m", "http://153.117.40.170:44217/Mozi.m", "http://110.186.229.108:47843/Mozi.m", "http://115.57.182.131:41041/Mozi.m", "http://183.63.8.194:46154/Mozi.m"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
UrlClickEvents | Ensure this data connector is enabled |
Here are the documented false positive scenarios and corresponding exclusions for the ThreatFox: Mozi IOCs detection rule:
Scenario: Legitimate Security Tool Updates
C:\Program Files\CrowdStrike\csagent.exe or C:\Windows\System32\MsMpEng.exe) when they are communicating with known update servers.Scenario: Scheduled Vulnerability Scanning
10.20.30.x) during their defined maintenance window (e.g., 02:00 – 04:00 UTC), filtering out any Mozi IOC matches generated by the scanner’s service process (java.exe or nessusd).Scenario: Third-Party Cloud Backup Operations