← Back to SOC feed Coverage →

ThreatFox: Mozi IOCs

ioc-hunt HIGH ThreatFox
UrlClickEvents
elf-moziiocthreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-09-04T11:00:00Z · Confidence: high

Hunt Hypothesis

This rule detects the presence of known Mozi botnet indicators, which are frequently used by adversaries to establish persistent command-and-control channels and execute remote code execution on compromised hosts. Proactively hunting for these IOCs in Azure Sentinel is critical because Mozi is a prevalent threat in IoT and server environments, allowing the SOC to identify and isolate infected assets before they are leveraged for lateral movement or data exfiltration.

IOC Summary

Malware Family: Mozi Total IOCs: 7 IOC Types: url

TypeValueThreat TypeFirst SeenConfidence
urlhxxp://223[.]123[.]35[.]122:44628/Mozi.mpayload_delivery2026-09-0475%
urlhxxp://115[.]57[.]204[.]186:60274/Mozi.mpayload_delivery2026-09-0475%
urlhxxp://105[.]198[.]0[.]3:37775/Mozi.mpayload_delivery2026-09-0475%
urlhxxp://139[.]135[.]59[.]203:59228/Mozi[.]7payload_delivery2026-09-0475%
urlhxxp://113[.]255[.]196[.]148:47674/Mozi.mpayload_delivery2026-09-0475%
urlhxxp://190[.]196[.]253[.]116:11818/Mozi.mpayload_delivery2026-09-0475%
urlhxxp://72[.]255[.]33[.]66:58752/Mozi.apayload_delivery2026-09-0475%

KQL: Url Hunt

// Hunt for access to known malicious URLs
// Source: ThreatFox - Mozi
let malicious_urls = dynamic(["http://223.123.35.122:44628/Mozi.m", "http://115.57.204.186:60274/Mozi.m", "http://105.198.0.3:37775/Mozi.m", "http://139.135.59.203:59228/Mozi.7", "http://113.255.196.148:47674/Mozi.m", "http://190.196.253.116:11818/Mozi.m", "http://72.255.33.66:58752/Mozi.a"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
UrlClickEventsEnsure this data connector is enabled

References

False Positive Guidance

Original source: https://threatfox.abuse.ch/browse/malware/elf.mozi/