This detection identifies adversary activity by monitoring network and endpoint telemetry for six specific Indicators of Compromise (IOCs) linked to the Mozi threat actor. A proactive hunt is essential in Azure Sentinel because Mozi’s sophisticated supply chain attack patterns often evade standard rule-based alerts, requiring manual correlation to uncover early-stage compromises before lateral movement occurs.
Malware Family: Mozi Total IOCs: 6 IOC Types: url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| url | hxxp://103[.]26[.]82[.]216:35366/Mozi.m | payload_delivery | 2026-08-30 | 75% |
| url | hxxp://139[.]135[.]42[.]31:43969/Mozi.m | payload_delivery | 2026-08-30 | 75% |
| url | hxxp://116[.]109[.]33[.]252:33235/Mozi.a | payload_delivery | 2026-08-30 | 75% |
| url | hxxp://112[.]25[.]235[.]194:60134/Mozi[.]7 | payload_delivery | 2026-08-30 | 75% |
| url | hxxp://175[.]107[.]0[.]8:44034/Mozi[.]7 | payload_delivery | 2026-08-30 | 75% |
| url | hxxp://153[.]117[.]37[.]70:33874/Mozi.m | payload_delivery | 2026-08-30 | 75% |
// Hunt for access to known malicious URLs
// Source: ThreatFox - Mozi
let malicious_urls = dynamic(["http://103.26.82.216:35366/Mozi.m", "http://139.135.42.31:43969/Mozi.m", "http://116.109.33.252:33235/Mozi.a", "http://112.25.235.194:60134/Mozi.7", "http://175.107.0.8:44034/Mozi.7", "http://153.117.37.70:33874/Mozi.m"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
UrlClickEvents | Ensure this data connector is enabled |
Scenario: Automated Security Tool Updates
svc-antivirus-update) and processes running within the trusted path C:\Program Files\CrowdStrike\ or C:\ProgramData\Microsoft Defender\.Scenario: Scheduled Backup Jobs
Veeam.Backup.Service.exe or rubrik-agent.Scenario: Third-Party SaaS Integration Sync