← Back to SOC feed Coverage →

ThreatFox: Mozi IOCs

ioc-hunt HIGH ThreatFox
UrlClickEvents
elf-moziiocthreatfox
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at ThreatFox →
Retrieved: 2026-08-21T11:00:00Z · Confidence: high

Hunt Hypothesis

This detection rule identifies adversary activity linked to the Mozi threat actor by monitoring for three specific indicators of compromise (IOCs) within Azure Sentinel logs. A proactive hunt is essential because Mozi’s targeted campaigns often involve early-stage reconnaissance that may evade standard alerting, requiring manual correlation to prevent potential lateral movement and data exfiltration.

IOC Summary

Malware Family: Mozi Total IOCs: 3 IOC Types: url

TypeValueThreat TypeFirst SeenConfidence
urlhxxp://110[.]38[.]2[.]86:48915/Mozi.mpayload_delivery2026-08-2175%
urlhxxp://39[.]34[.]140[.]102:40567/Mozi.apayload_delivery2026-08-2175%
urlhxxp://153[.]117[.]38[.]146:46962/Mozi.apayload_delivery2026-08-2175%

KQL: Url Hunt

// Hunt for access to known malicious URLs
// Source: ThreatFox - Mozi
let malicious_urls = dynamic(["http://110.38.2.86:48915/Mozi.m", "http://39.34.140.102:40567/Mozi.a", "http://153.117.38.146:46962/Mozi.a"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc

Required Data Sources

Sentinel TableNotes
UrlClickEventsEnsure this data connector is enabled

References

False Positive Guidance

Here are 4 specific false positive scenarios for the ThreatFox: Mozi IOCs detection rule, including suggested filters and exclusions tailored for an enterprise environment:

Original source: https://threatfox.abuse.ch/browse/malware/elf.mozi/