← Back to SOC feed Coverage →

ThreatFox: Mozi IOCs

ioc-hunt HIGH ThreatFox
UrlClickEvents
elf-moziiocthreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-09-02T23:00:00Z · Confidence: high

Hunt Hypothesis

This hypothesis targets the presence of known Mozi botnet indicators, which are frequently used to establish persistent backdoors and facilitate command-and-control channels for ransomware deployment. Proactively hunting for these IOCs in Azure Sentinel is critical because Mozi often serves as an initial access vector for high-impact attacks, allowing the SOC to identify compromised assets before they are leveraged for lateral movement or data exfiltration.

IOC Summary

Malware Family: Mozi Total IOCs: 4 IOC Types: url

TypeValueThreat TypeFirst SeenConfidence
urlhxxp://72[.]255[.]26[.]49:39564/Mozi.mpayload_delivery2026-09-0275%
urlhxxp://72[.]255[.]15[.]152:50287/Mozi.mpayload_delivery2026-09-0275%
urlhxxp://103[.]18[.]14[.]56:59567/Mozi.mpayload_delivery2026-09-0275%
urlhxxp://72[.]255[.]37[.]113:54826/Mozi.mpayload_delivery2026-09-0275%

KQL: Url Hunt

// Hunt for access to known malicious URLs
// Source: ThreatFox - Mozi
let malicious_urls = dynamic(["http://72.255.26.49:39564/Mozi.m", "http://72.255.15.152:50287/Mozi.m", "http://103.18.14.56:59567/Mozi.m", "http://72.255.37.113:54826/Mozi.m"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
UrlClickEventsEnsure this data connector is enabled

References

False Positive Guidance

Original source: https://threatfox.abuse.ch/browse/malware/elf.mozi/