TF-1932516
high
📛 Threat Title
Mozi: URL that delivers a malware payload http://124.29.194.194:43904/Mozi.7
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mozi. Confidence: 75. First seen: 2026-09-25 06:28:07 UTC. Reporter: HoneyLabs. Tags: elf, IoT, Mozi.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://124.29.194.194:43904/mozi.7
IOC database
- Type
- url
- Value
http://124.29.194.194:43904/mozi.7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that delivers a malware payload attributed to Mozi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mozi. Confidence: 75. First seen: 2026-09-25 06:28:07 UTC. Reporter: HoneyLabs. Tags: elf, IoT, Mozi.
Remediations (10)
-
web:davidgodwinpratt.com
Hunt Hypothesis The ThreatFox: Mozi IOCs rule detects potential adversary activity linked to the Mozi malware family by identifying known indicators of compromise associated with its command and control infrastructure. SOC teams should proactively hunt for these IOCs in Azure Sentinel to identify and mitigate advanced persistent threats leveraging Mozi before significant data exfiltration or ...
-
web:davidgodwinpratt.com
Hunt Hypothesis This detection identifies adversary activity involving the Mozi malware family by monitoring traffic to a curated set of 34 known malicious URLs that facilitate command-and-control communication or initial payload delivery. A proactive hunt is essential in Azure Sentinel to rapidly isolate compromised endpoints and prevent lateral movement, as Mozi's high severity rating ...
-
web:hunt.io
Discover how the Mozi botnet exploits IoT vulnerabilities, its evolution, targeted sectors, and strategies to protect your devices from this persistent threat.
-
web:ismalicious.com
1,182 indicators of compromise attributed to the Mozi malware family — domains, IPs, URLs and file hashes, from abuse.ch feeds.
-
web:kinryu.sh
The analysis classifies the sample as Mozi and types it as a DDoS bot, a worm and a loader in one statically linked binary; a loader is a small first-stage program whose only job is to fetch and start the real payload . The bencode KRPC handling and the acsMozi / Mozi.m artefacts are the family signature.
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http ://124.29.194.65:59822/ Mozi .m.
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http ://124.29.251.97:53991/ Mozi .m.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.huntress.com
Mozi is a nasty piece of work derived from the source code of other IoT malware families like Mirai, Gafgyt, and IoT Reaper. It primarily functions as a P2P botnet, meaning infected devices communicate directly with each other instead of a centralized command-and-control (C2) server.
-
web:www.microsoft.com
Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs). It works by exploiting weak telnet passwords1 and nearly a dozen unpatched IoT vulnerabilities2 and it's been used to conduct distributed denial-of-service (DDoS) attacks, data exfiltration, and command or payload execution.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.