OTX-686e31099dfe2eeb93e15a4d
high
📛 Threat Title
Mozi Botnet - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Mozi Botnet Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 1 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (13)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
115.48.55.41
IOC database
- Type
- ipv4
- Value
115.48.55.41- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
182.124.232.250
IOC database
- Type
- ipv4
- Value
182.124.232.250- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
168.227.148.151
IOC database
- Type
- ipv4
- Value
168.227.148.151- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
46.99.251.91
IOC database
- Type
- ipv4
- Value
46.99.251.91- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
59.96.136.199
IOC database
- Type
- ipv4
- Value
59.96.136.199- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
123.14.218.45
IOC database
- Type
- ipv4
- Value
123.14.218.45- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
115.54.108.130
IOC database
- Type
- ipv4
- Value
115.54.108.130- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
46.99.151.227
IOC database
- Type
- ipv4
- Value
46.99.151.227- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
42.224.96.49
IOC database
- Type
- ipv4
- Value
42.224.96.49- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
103.42.142.59
1 feed
IOC database
- Type
- ipv4
- Value
103.42.142.59- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Ipsum. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
112.242.178.250
IOC database
- Type
- ipv4
- Value
112.242.178.250- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Mozi
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
125.43.44.207
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/125.43.44.207
IOC database
- Type
- ipv4
- Value
125.43.44.207- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/125.43.44.207
ipv4
110.37.35.199
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/110.37.35.199
IOC database
- Type
- ipv4
- Value
110.37.35.199- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/110.37.35.199
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Mozi Botnet Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:axelarator.github.io
Discovered in 2019, Mozi is a P2P botnet using the DHT protocol that spreads via Telnet with weak passwords and known exploits. Evolved from the source code of several known malware families; Gafgyt, Mirai and IoT Reaper, Mozi is capable of DDoS attacks, data exfiltration and command or payload execution. The malware targets IoT devices, predominantly routers and DVRs that are either unpatched ...
-
web:github.com
C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/ botnet / C2 infrastructure.
-
web:nordvpn.com
Mozi is a IoT botnet that employs P2P communication and source codes of other well-known malware families to steal sensitive data.
-
web:www.botconf.eu
Mozi implements a peer-to-peer (P2P) command-and-control ( C2 ) channel based on the BitTorrent protocol. This makes Mozi an interesting target for analysis as it allows to gather intelligence on the infection population across IoT devices.
-
web:www.cloudsek.com
The Androxgh0st botnet , an emerging cyber threat since January 2024, has resurfaced with advanced capabilities and integration of IoT-focused Mozi payloads. Exploiting over 20 vulnerabilities in technologies like Cisco ASA, Atlassian JIRA, PHP frameworks, and IoT devices, Androxgh0st enables unauthorized access and remote code execution. Its growing sophistication includes shared ...
-
web:www.huntress.com
Mozi is a nasty piece of work derived from the source code of other IoT malware families like Mirai, Gafgyt, and IoT Reaper. It primarily functions as a P2P botnet , meaning infected devices communicate directly with each other instead of a centralized command-and-control ( C2 ) server.
-
web:www.ibm.com
The botnet attack Mozi builds on Mirai to infect IoT devices. Learn the details of this botnet , see how to spot it, and check up on your IoT security.
-
web:www.microsoft.com
Mozi is a peer-to-peer (P2P) botnet that uses a BitTorrent-like network to infect IoT devices such as network gateways and digital video records (DVRs). It works by exploiting weak telnet passwords1 and nearly a dozen unpatched IoT vulnerabilities2 and it's been used to conduct distributed denial-of-service (DDoS) attacks, data exfiltration, and command or payload execution.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.