s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.mozi

📛 Threat Title

Malware family: Mozi

Category: Mozi First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.mozi`. Printable name: Mozi.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.mozi VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.mozi

IOC database

Type
domain
Value
elf.mozi
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.mozi

References (1)

Remediations (10)

  • web:linuxvox.com

    CERT (Computer Emergency Response Team) advisories on the Mozi Botnet This blog post provides a comprehensive overview of the Trojan Linux Mozi Botnet, but it's important to note that the threat landscape is constantly evolving. Stay updated with the latest security news and advisories to protect your systems effectively.

  • web:malpedia.caad.fkie.fraunhofer.de

    Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.

  • web:malwaretips.com

    Mozi malware botnet activity faded away in August after a mysterious unknown party sent a payload on September 27, 2023, that triggered a kill switch to deactivate all bots. Mozi is a well-known DDoS (distributed denial of service) malware botnet that emerged in 2019, primarily targeting IoT...

  • web:thehackernews.com

    "A week later, on August 16, the same thing happened in China. While the mysterious control payload - aka kill switch - stripped Mozi bots of most functionality, they maintained persistence." Mozi is an Internet of Things (IoT) botnet that emerged from the source code of several known malware families, such as Gafgyt, Mirai, and IoT Reaper.

  • web:www.elastic.co

    The Mozi botnet is an ongoing malware campaign targeting unsecured and vulnerable networking devices. This post will showcase the analyst journey of collecting, analyzing, and operationalizing threat data from the Mozi botnet.

  • web:www.huntress.com

    Learn what Mozi IoT Botnet malware is, how it spreads, and how to detect and remove it before it impacts your systems.

  • web:www.microsoft.com

    Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs). It works by exploiting weak telnet passwords1 and nearly a dozen unpatched IoT vulnerabilities2 and it's been used to conduct distributed denial-of-service (DDoS) attacks, data exfiltration, and command or payload execution.

  • web:www.rivitmedia.com

    The Mozi virus, a sophisticated and evolving Trojan, has emerged as a significant cyber threat targeting Internet of Things (IoT) devices. Leveraging peer-to-peer (P2P) networks for communication, this malware is notorious for its ability to evade traditional detection methods and maintain persistent control over infected devices.

  • web:www.techradar.com

    A major malware botnet known as Mozi suddenly terminated its operations at the end of September, and no one seems to know exactly why.

  • web:www.welivesecurity.com

    In August 2023, the notorious Mozi botnet, infamous for exploiting vulnerabilities in hundreds of thousands of IoT devices each year, experienced a sudden and unanticipated nosedive in activity.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.