s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1868460 high

📛 Threat Title

Mozi: URL that delivers a malware payload http://139.135.42.179:41902/Mozi.m

Category: Mozi Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mozi. Confidence: 75. First seen: 2026-08-04 18:19:13 UTC. Reporter: HoneyLabs. Tags: elf, IoT, Mozi.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url http://139.135.42.179:41902/mozi.m

IOC database

Type
url
Value
http://139.135.42.179:41902/mozi.m
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to Mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mozi. Confidence: 75. First seen: 2026-08-04 18:19:13 UTC. Reporter: HoneyLabs. Tags: elf, IoT, Mozi.

Remediations (10)

  • web:hunt.io

    Discover how the Mozi botnet exploits IoT vulnerabilities, its evolution, targeted sectors, and strategies to protect your devices from this persistent threat.

  • web:ismalicious.com

    400 indicators (0 domains, 28 IPs, 369 URLs , 3 hashes) attributed to the Mozi malware family.

  • web:thehackernews.com

    The threat actors behind the AndroxGh0st malware are now exploiting a broader set of security flaws impacting various internet-facing applications, while also deploying the Mozi botnet malware . "This botnet utilizes remote code execution and credential-stealing methods to maintain persistent access ...

  • web:urlhaus.abuse.ch

    URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...

  • web:www.cloudsek.com

    The Androxgh0st botnet, an emerging cyber threat since January 2024, has resurfaced with advanced capabilities and integration of IoT-focused Mozi payloads . Exploiting over 20 vulnerabilities in technologies like Cisco ASA, Atlassian JIRA, PHP frameworks, and IoT devices, Androxgh0st enables unauthorized access and remote code execution. Its growing sophistication includes shared ...

  • web:www.csk.gov.in

    It has been reported that a new malware named Mozi is affecting IoT devices globally. Affected IoT devices are being assembled into an IoT botnet which could be employed by botnet owner for launching distributed denial-of-service (DDoS) attacks, data exfiltration and payload execution. According to the reports, Mozi malware is comprised of source code from Gafgyt, Mirai, and IoT Reaper ...

  • web:www.huntress.com

    Mozi is a nasty piece of work derived from the source code of other IoT malware families like Mirai, Gafgyt, and IoT Reaper. It primarily functions as a P2P botnet, meaning infected devices communicate directly with each other instead of a centralized command-and-control (C2) server.

  • web:www.ibm.com

    A relatively new player in the threat arena, the Mozi botnet, has spiked among Internet of things (IoT) devices, IBM X-Force has discovered. This malware has been active since late 2019 and has code overlap with Mirai and its variants. Mozi accounted for nearly 90% of the observed IoT network traffic from October 2019 through June 2020. This startling takeover was accompanied by a huge ...

  • web:www.microsoft.com

    Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs). It works by exploiting weak telnet passwords1 and nearly a dozen unpatched IoT vulnerabilities2 and it's been used to conduct distributed denial-of-service (DDoS) attacks, data exfiltration, and command or payload execution.

  • web:www.welivesecurity.com

    In August 2023, the notorious Mozi botnet, infamous for exploiting vulnerabilities in hundreds of thousands of IoT devices each year, experienced a sudden and unanticipated nosedive in activity.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.