MB-50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059
high
📛 Threat Title
Mozi: 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059
Description
File type: elf. Size: 70463 bytes. Tags: cowrie, elf, honeypot, mips, Mozi. Reporter: aLittleBitGrey. First seen: 2026-09-25 11:17:21.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059
VT 26 / 75
IOC database
- Type
- hash_sha256
- Value
50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mozi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Linux.Truncpx.99968 |
| ALYac | malicious | Trojan.Linux.Mozi.11 |
| Antiy-AVL | malicious | Trojan/Linux.Gafgyt.a |
| Arcabit | malicious | Trojan.Linux.Mozi.11 |
| Avast | malicious | ELF:Agent-BMN [Trj] |
| AVG | malicious | ELF:Agent-BMN [Trj] |
| Avira | malicious | TR/LINUX.Agent.BMN |
| BitDefender | malicious | Trojan.Linux.Mozi.11 |
| CTX | malicious | elf.trojan.mozi |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Packed.1255 |
| Elastic | malicious | Linux.Packer.Patched.UPX |
| Emsisoft | malicious | Trojan.Linux.Mozi.11 (B) |
| F-Secure | malicious | Trojan.TR/LINUX.Agent.BMN |
| Fortinet | malicious | ELF/GenericKD.7945!tr |
| GData | malicious | Trojan.Linux.Mozi.11 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan.Linux.Generic |
| Jiangmin | malicious | Backdoor.Linux.fmhj |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.Mozi.11 |
| Skyhigh | malicious | GenericRXNR-GD!7BC30B1D8151 |
| Tencent | malicious | Risktool.Linux.Agent.dt |
| TrellixENS | malicious | GenericRXNR-GD!7BC30B1D8151 |
| VBA32 | malicious | Trojan.Linux.Mirai |
| VIPRE | malicious | Trojan.Linux.Mozi.11 |
Details From VirusTotal
Basic Properties
| MD5 | 7bc30b1d81513b264ec90331cab225e9 |
| SHA-1 | f238db56a6900c4d1d57975ea28373dff0f652e8 |
| SHA-256 | 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059 |
| VHash | 04ca467c0cd9a3ff64f54ccacb1f8003 |
| SSDEEP | 1536:XtBTX941eYF8NblpuvnwanQ3zWYq40LZ51g6o:biMYFJvw6Yh0b1g7 |
| TLSH | T15363023867130D9DC0363CFAF58ED66329C71F29304B005511B9E6BA5FF729CA8E9226 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header |
| File size | 68.8 KB |
History
| First seen on VirusTotal | 2026-09-25 11:20 UTC |
| Last submission | 2026-09-25 11:20 UTC |
| Last analysis | 2026-09-25 11:20 UTC |
| Last modified on VirusTotal | 2026-09-25 13:46 UTC |
Known Names
t91zfv.exe4tasu8.exe50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059.elf
hash_sha1
f238db56a6900c4d1d57975ea28373dff0f652e8
VT 26 / 75
IOC database
- Type
- hash_sha1
- Value
f238db56a6900c4d1d57975ea28373dff0f652e8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Linux.Truncpx.99968 |
| ALYac | malicious | Trojan.Linux.Mozi.11 |
| Antiy-AVL | malicious | Trojan/Linux.Gafgyt.a |
| Arcabit | malicious | Trojan.Linux.Mozi.11 |
| Avast | malicious | ELF:Agent-BMN [Trj] |
| AVG | malicious | ELF:Agent-BMN [Trj] |
| Avira | malicious | TR/LINUX.Agent.BMN |
| BitDefender | malicious | Trojan.Linux.Mozi.11 |
| CTX | malicious | elf.trojan.mozi |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Packed.1255 |
| Elastic | malicious | Linux.Packer.Patched.UPX |
| Emsisoft | malicious | Trojan.Linux.Mozi.11 (B) |
| F-Secure | malicious | Trojan.TR/LINUX.Agent.BMN |
| Fortinet | malicious | ELF/GenericKD.7945!tr |
| GData | malicious | Trojan.Linux.Mozi.11 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan.Linux.Generic |
| Jiangmin | malicious | Backdoor.Linux.fmhj |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.Mozi.11 |
| Skyhigh | malicious | GenericRXNR-GD!7BC30B1D8151 |
| Tencent | malicious | Risktool.Linux.Agent.dt |
| TrellixENS | malicious | GenericRXNR-GD!7BC30B1D8151 |
| VBA32 | malicious | Trojan.Linux.Mirai |
| VIPRE | malicious | Trojan.Linux.Mozi.11 |
Details From VirusTotal
Basic Properties
| MD5 | 7bc30b1d81513b264ec90331cab225e9 |
| SHA-1 | f238db56a6900c4d1d57975ea28373dff0f652e8 |
| SHA-256 | 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059 |
| VHash | 04ca467c0cd9a3ff64f54ccacb1f8003 |
| SSDEEP | 1536:XtBTX941eYF8NblpuvnwanQ3zWYq40LZ51g6o:biMYFJvw6Yh0b1g7 |
| TLSH | T15363023867130D9DC0363CFAF58ED66329C71F29304B005511B9E6BA5FF729CA8E9226 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header |
| File size | 68.8 KB |
History
| First seen on VirusTotal | 2026-09-25 11:20 UTC |
| Last submission | 2026-09-25 11:20 UTC |
| Last analysis | 2026-09-25 11:20 UTC |
| Last modified on VirusTotal | 2026-09-25 13:46 UTC |
Known Names
t91zfv.exe4tasu8.exe50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059.elf
hash_md5
7bc30b1d81513b264ec90331cab225e9
VT 26 / 75
IOC database
- Type
- hash_md5
- Value
7bc30b1d81513b264ec90331cab225e9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Linux.Truncpx.99968 |
| ALYac | malicious | Trojan.Linux.Mozi.11 |
| Antiy-AVL | malicious | Trojan/Linux.Gafgyt.a |
| Arcabit | malicious | Trojan.Linux.Mozi.11 |
| Avast | malicious | ELF:Agent-BMN [Trj] |
| AVG | malicious | ELF:Agent-BMN [Trj] |
| Avira | malicious | TR/LINUX.Agent.BMN |
| BitDefender | malicious | Trojan.Linux.Mozi.11 |
| CTX | malicious | elf.trojan.mozi |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Packed.1255 |
| Elastic | malicious | Linux.Packer.Patched.UPX |
| Emsisoft | malicious | Trojan.Linux.Mozi.11 (B) |
| F-Secure | malicious | Trojan.TR/LINUX.Agent.BMN |
| Fortinet | malicious | ELF/GenericKD.7945!tr |
| GData | malicious | Trojan.Linux.Mozi.11 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan.Linux.Generic |
| Jiangmin | malicious | Backdoor.Linux.fmhj |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.Mozi.11 |
| Skyhigh | malicious | GenericRXNR-GD!7BC30B1D8151 |
| Tencent | malicious | Risktool.Linux.Agent.dt |
| TrellixENS | malicious | GenericRXNR-GD!7BC30B1D8151 |
| VBA32 | malicious | Trojan.Linux.Mirai |
| VIPRE | malicious | Trojan.Linux.Mozi.11 |
Details From VirusTotal
Basic Properties
| MD5 | 7bc30b1d81513b264ec90331cab225e9 |
| SHA-1 | f238db56a6900c4d1d57975ea28373dff0f652e8 |
| SHA-256 | 50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059 |
| VHash | 04ca467c0cd9a3ff64f54ccacb1f8003 |
| SSDEEP | 1536:XtBTX941eYF8NblpuvnwanQ3zWYq40LZ51g6o:biMYFJvw6Yh0b1g7 |
| TLSH | T15363023867130D9DC0363CFAF58ED66329C71F29304B005511B9E6BA5FF729CA8E9226 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header |
| File size | 68.8 KB |
History
| First seen on VirusTotal | 2026-09-25 11:20 UTC |
| Last submission | 2026-09-25 11:20 UTC |
| Last analysis | 2026-09-25 11:20 UTC |
| Last modified on VirusTotal | 2026-09-25 13:46 UTC |
Known Names
t91zfv.exe4tasu8.exe50c5afa355802712b81434c3869c978d490f84a37831a2ff1d1041aaf2dbf059.elf
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 70463 bytes. Tags: cowrie, elf, honeypot, mips, Mozi. Reporter: aLittleBitGrey. First seen: 2026-09-25 11:17:21.
Remediations (10)
-
web:apps.microsoft.com
Choose the browser that prioritizes you, not their bottom line. Don't settle for the default browser. When you choose Firefox, you protect your data while supporting the non-profit Mozilla Foundation, whose mission is to build a better internet that's safe and accessible for everyone, everywhere. Join the hundreds of millions of people who choose to protect what's important by using Firefox, a ...
-
web:en.wikipedia.org
Mozi , [note 1] personal name Mo Di, [note 2][3] was a Chinese philosopher, logician, and the founder of the Mohist school of thought, making him one of the most important figures of the Warring States period (c. 475 - 221 BCE). Alongside Confucianism, Mohism became the most prominent organized school of the Hundred Schools of Thought throughout the period. The Mozi is an anthology of ...
-
web:www.firefox.com
The independent browser that has your back. Firefox blocks trackers, has a free built-in VPN, puts you in control of AI, and never sells your personal data.
-
web:www.firefox.com
Choose which Firefox Browser to download in your language Everyone deserves access to the internet — your language should never be a barrier. That's why — with the help of dedicated volunteers around the world — we make Firefox available in more than 90 languages.
-
web:www.huntress.com
Learn what Mozi IoT Botnet malware is, how it spreads, and how to detect and remove it before it impacts your systems.
-
web:www.mozi.app
Mozi is a private social network for seeing your people more, IRL. Add your plans, check who's in town, and know when you overlap.
-
web:www.mozilla.org
Mozilla is the not-for-profit behind the lightning fast Firefox browser. We put people over profit to give everyone more power online.
-
web:www.mozilla.org
We're working to put control of the internet back in the hands of the people using it.
-
web:www.threatclaw.ai
The interesting structural point is the co-tenancy of Mozi and Mirai artifacts in the same 24h window from the same IP-range class. Mozi and Mirai are historically competing IoT botnets optimizing for overlapping device populations (embedded Linux, routers, DVRs, IoT gateways). A concurrent dual-rail rollout is consistent with either:
-
web:www.youtube.com
100 Days transforming a Desert Village should be out in the next few days! This video took me a little longer due to being a much larger project than the last few. Also, for those of you who have ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.