s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-686e31099dfe2eeb93e15a4d high

📛 Threat Title

Mozi Botnet - C2 IP/Domain Tracker

Category: Mozi Botnet Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to Mozi Botnet Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 1 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (13)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 115.48.55.41

IOC database

Type
ipv4
Value
115.48.55.41
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 182.124.232.250

IOC database

Type
ipv4
Value
182.124.232.250
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 168.227.148.151

IOC database

Type
ipv4
Value
168.227.148.151
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 46.99.251.91

IOC database

Type
ipv4
Value
46.99.251.91
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 59.96.136.199

IOC database

Type
ipv4
Value
59.96.136.199
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 123.14.218.45

IOC database

Type
ipv4
Value
123.14.218.45
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 115.54.108.130

IOC database

Type
ipv4
Value
115.54.108.130
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 46.99.151.227

IOC database

Type
ipv4
Value
46.99.151.227
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 42.224.96.49

IOC database

Type
ipv4
Value
42.224.96.49
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 103.42.142.59 1 feed

IOC database

Type
ipv4
Value
103.42.142.59
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Ipsum. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 112.242.178.250

IOC database

Type
ipv4
Value
112.242.178.250
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 125.43.44.207 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/125.43.44.207

IOC database

Type
ipv4
Value
125.43.44.207
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/125.43.44.207

ipv4 110.37.35.199 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/110.37.35.199

IOC database

Type
ipv4
Value
110.37.35.199
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/110.37.35.199

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to Mozi Botnet Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:axelarator.github.io

    Discovered in 2019, Mozi is a P2P botnet using the DHT protocol that spreads via Telnet with weak passwords and known exploits. Evolved from the source code of several known malware families; Gafgyt, Mirai and IoT Reaper, Mozi is capable of DDoS attacks, data exfiltration and command or payload execution. The malware targets IoT devices, predominantly routers and DVRs that are either unpatched ...

  • web:github.com

    C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/ botnet / C2 infrastructure.

  • web:nordvpn.com

    Mozi is a IoT botnet that employs P2P communication and source codes of other well-known malware families to steal sensitive data.

  • web:www.botconf.eu

    Mozi implements a peer-to-peer (P2P) command-and-control ( C2 ) channel based on the BitTorrent protocol. This makes Mozi an interesting target for analysis as it allows to gather intelligence on the infection population across IoT devices.

  • web:www.cloudsek.com

    The Androxgh0st botnet , an emerging cyber threat since January 2024, has resurfaced with advanced capabilities and integration of IoT-focused Mozi payloads. Exploiting over 20 vulnerabilities in technologies like Cisco ASA, Atlassian JIRA, PHP frameworks, and IoT devices, Androxgh0st enables unauthorized access and remote code execution. Its growing sophistication includes shared ...

  • web:www.huntress.com

    Mozi is a nasty piece of work derived from the source code of other IoT malware families like Mirai, Gafgyt, and IoT Reaper. It primarily functions as a P2P botnet , meaning infected devices communicate directly with each other instead of a centralized command-and-control ( C2 ) server.

  • web:www.ibm.com

    The botnet attack Mozi builds on Mirai to infect IoT devices. Learn the details of this botnet , see how to spot it, and check up on your IoT security.

  • web:www.microsoft.com

    Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs). It works by exploiting weak telnet passwords1 and nearly a dozen unpatched IoT vulnerabilities2 and it's been used to conduct distributed denial-of-service (DDoS) attacks, data exfiltration, and command or payload execution.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…