s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059 high

📛 Threat Title

Mozi: 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059

Category: Mozi Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 70463 bytes. Tags: cowrie, elf, honeypot, mips, Mozi. Reporter: aLittleBitGrey. First seen: 2026-09-25 11:17:21.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059 VT 26 / 75

IOC database

Type
hash_sha256
Value
50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 26 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Linux.Truncpx.99968
ALYac malicious Trojan.Linux.Mozi.11
Antiy-AVL malicious Trojan/Linux.Gafgyt.a
Arcabit malicious Trojan.Linux.Mozi.11
Avast malicious ELF:Agent-BMN [Trj]
AVG malicious ELF:Agent-BMN [Trj]
Avira malicious TR/LINUX.Agent.BMN
BitDefender malicious Trojan.Linux.Mozi.11
CTX malicious elf.trojan.mozi
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Packed.1255
Elastic malicious Linux.Packer.Patched.UPX
Emsisoft malicious Trojan.Linux.Mozi.11 (B)
F-Secure malicious Trojan.TR/LINUX.Agent.BMN
Fortinet malicious ELF/GenericKD.7945!tr
GData malicious Trojan.Linux.Mozi.11
Google malicious Detected
Ikarus malicious Trojan.Linux.Generic
Jiangmin malicious Backdoor.Linux.fmhj
Microsoft malicious Trojan:Script/Wacatac.B!ml
MicroWorld-eScan malicious Trojan.Linux.Mozi.11
Skyhigh malicious GenericRXNR-GD!7BC30B1D8151
Tencent malicious Risktool.Linux.Agent.dt
TrellixENS malicious GenericRXNR-GD!7BC30B1D8151
VBA32 malicious Trojan.Linux.Mirai
VIPRE malicious Trojan.Linux.Mozi.11

Details From VirusTotal

Basic Properties
MD57bc30b1d81513b264ec90331cab225e9
SHA-1f238db56a6900c4d1d57975ea28373dff0f652e8
SHA-25650c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059
VHash04ca467c0cd9a3ff64f54ccacb1f8003
SSDEEP1536:XtBTX941eYF8NblpuvnwanQ3zWYq40LZ51g6o:biMYFJvw6Yh0b1g7
TLSHT15363023867130D9DC0363CFAF58ED66329C71F29304B005511B9E6BA5FF729CA8E9226
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
File size68.8 KB
History
First seen on VirusTotal2026-09-25 11:20 UTC
Last submission2026-09-25 11:20 UTC
Last analysis2026-09-25 11:20 UTC
Last modified on VirusTotal2026-09-25 13:46 UTC
Known Names
  • t91zfv.exe
  • 4tasu8.exe
  • 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059.elf
hash_sha1 f238db56a6900c4d1d57975ea28373dff0f652e8 VT 26 / 75

IOC database

Type
hash_sha1
Value
f238db56a6900c4d1d57975ea28373dff0f652e8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 26 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Linux.Truncpx.99968
ALYac malicious Trojan.Linux.Mozi.11
Antiy-AVL malicious Trojan/Linux.Gafgyt.a
Arcabit malicious Trojan.Linux.Mozi.11
Avast malicious ELF:Agent-BMN [Trj]
AVG malicious ELF:Agent-BMN [Trj]
Avira malicious TR/LINUX.Agent.BMN
BitDefender malicious Trojan.Linux.Mozi.11
CTX malicious elf.trojan.mozi
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Packed.1255
Elastic malicious Linux.Packer.Patched.UPX
Emsisoft malicious Trojan.Linux.Mozi.11 (B)
F-Secure malicious Trojan.TR/LINUX.Agent.BMN
Fortinet malicious ELF/GenericKD.7945!tr
GData malicious Trojan.Linux.Mozi.11
Google malicious Detected
Ikarus malicious Trojan.Linux.Generic
Jiangmin malicious Backdoor.Linux.fmhj
Microsoft malicious Trojan:Script/Wacatac.B!ml
MicroWorld-eScan malicious Trojan.Linux.Mozi.11
Skyhigh malicious GenericRXNR-GD!7BC30B1D8151
Tencent malicious Risktool.Linux.Agent.dt
TrellixENS malicious GenericRXNR-GD!7BC30B1D8151
VBA32 malicious Trojan.Linux.Mirai
VIPRE malicious Trojan.Linux.Mozi.11

Details From VirusTotal

Basic Properties
MD57bc30b1d81513b264ec90331cab225e9
SHA-1f238db56a6900c4d1d57975ea28373dff0f652e8
SHA-25650c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059
VHash04ca467c0cd9a3ff64f54ccacb1f8003
SSDEEP1536:XtBTX941eYF8NblpuvnwanQ3zWYq40LZ51g6o:biMYFJvw6Yh0b1g7
TLSHT15363023867130D9DC0363CFAF58ED66329C71F29304B005511B9E6BA5FF729CA8E9226
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
File size68.8 KB
History
First seen on VirusTotal2026-09-25 11:20 UTC
Last submission2026-09-25 11:20 UTC
Last analysis2026-09-25 11:20 UTC
Last modified on VirusTotal2026-09-25 13:46 UTC
Known Names
  • t91zfv.exe
  • 4tasu8.exe
  • 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059.elf
hash_md5 7bc30b1d81513b264ec90331cab225e9 VT 26 / 75

IOC database

Type
hash_md5
Value
7bc30b1d81513b264ec90331cab225e9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 26 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Linux.Truncpx.99968
ALYac malicious Trojan.Linux.Mozi.11
Antiy-AVL malicious Trojan/Linux.Gafgyt.a
Arcabit malicious Trojan.Linux.Mozi.11
Avast malicious ELF:Agent-BMN [Trj]
AVG malicious ELF:Agent-BMN [Trj]
Avira malicious TR/LINUX.Agent.BMN
BitDefender malicious Trojan.Linux.Mozi.11
CTX malicious elf.trojan.mozi
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Packed.1255
Elastic malicious Linux.Packer.Patched.UPX
Emsisoft malicious Trojan.Linux.Mozi.11 (B)
F-Secure malicious Trojan.TR/LINUX.Agent.BMN
Fortinet malicious ELF/GenericKD.7945!tr
GData malicious Trojan.Linux.Mozi.11
Google malicious Detected
Ikarus malicious Trojan.Linux.Generic
Jiangmin malicious Backdoor.Linux.fmhj
Microsoft malicious Trojan:Script/Wacatac.B!ml
MicroWorld-eScan malicious Trojan.Linux.Mozi.11
Skyhigh malicious GenericRXNR-GD!7BC30B1D8151
Tencent malicious Risktool.Linux.Agent.dt
TrellixENS malicious GenericRXNR-GD!7BC30B1D8151
VBA32 malicious Trojan.Linux.Mirai
VIPRE malicious Trojan.Linux.Mozi.11

Details From VirusTotal

Basic Properties
MD57bc30b1d81513b264ec90331cab225e9
SHA-1f238db56a6900c4d1d57975ea28373dff0f652e8
SHA-25650c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059
VHash04ca467c0cd9a3ff64f54ccacb1f8003
SSDEEP1536:XtBTX941eYF8NblpuvnwanQ3zWYq40LZ51g6o:biMYFJvw6Yh0b1g7
TLSHT15363023867130D9DC0363CFAF58ED66329C71F29304B005511B9E6BA5FF729CA8E9226
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
File size68.8 KB
History
First seen on VirusTotal2026-09-25 11:20 UTC
Last submission2026-09-25 11:20 UTC
Last analysis2026-09-25 11:20 UTC
Last modified on VirusTotal2026-09-25 13:46 UTC
Known Names
  • t91zfv.exe
  • 4tasu8.exe
  • 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059.elf

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 70463 bytes. Tags: cowrie, elf, honeypot, mips, Mozi. Reporter: aLittleBitGrey. First seen: 2026-09-25 11:17:21.

Remediations (10)

  • web:apps.microsoft.com

    Choose the browser that prioritizes you, not their bottom line. Don't settle for the default browser. When you choose Firefox, you protect your data while supporting the non-profit Mozilla Foundation, whose mission is to build a better internet that's safe and accessible for everyone, everywhere. Join the hundreds of millions of people who choose to protect what's important by using Firefox, a ...

  • web:en.wikipedia.org

    Mozi , [note 1] personal name Mo Di, [note 2][3] was a Chinese philosopher, logician, and the founder of the Mohist school of thought, making him one of the most important figures of the Warring States period (c. 475 - 221 BCE). Alongside Confucianism, Mohism became the most prominent organized school of the Hundred Schools of Thought throughout the period. The Mozi is an anthology of ...

  • web:www.firefox.com

    The independent browser that has your back. Firefox blocks trackers, has a free built-in VPN, puts you in control of AI, and never sells your personal data.

  • web:www.firefox.com

    Choose which Firefox Browser to download in your language Everyone deserves access to the internet — your language should never be a barrier. That's why — with the help of dedicated volunteers around the world — we make Firefox available in more than 90 languages.

  • web:www.huntress.com

    Learn what Mozi IoT Botnet malware is, how it spreads, and how to detect and remove it before it impacts your systems.

  • web:www.mozi.app

    Mozi is a private social network for seeing your people more, IRL. Add your plans, check who's in town, and know when you overlap.

  • web:www.mozilla.org

    Mozilla is the not-for-profit behind the lightning fast Firefox browser. We put people over profit to give everyone more power online.

  • web:www.mozilla.org

    We're working to put control of the internet back in the hands of the people using it.

  • web:www.threatclaw.ai

    The interesting structural point is the co-tenancy of Mozi and Mirai artifacts in the same 24h window from the same IP-range class. Mozi and Mirai are historically competing IoT botnets optimizing for overlapping device populations (embedded Linux, routers, DVRs, IoT gateways). A concurrent dual-rail rollout is consistent with either:

  • web:www.youtube.com

    100 Days transforming a Desert Village should be out in the next few days! This video took me a little longer due to being a much larger project than the last few. Also, for those of you who have ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.