This detection identifies adversary activity involving the Mozi malware family by flagging network traffic to nine known malicious URLs that facilitate command and control or payload delivery. A SOC team should proactively hunt for these indicators in Azure Sentinel to rapidly isolate compromised endpoints before the malware establishes persistence or exfiltrates sensitive data.
Threat: Mozi Total URLs: 9 Active URLs: 9
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://115.56.149.89:38790/i | online | malware_download | 2026-07-27 |
hxxp://115.56.149.89:38790/bin.sh | online | malware_download | 2026-07-27 |
hxxp://222.134.164.39:49784/i | online | malware_download | 2026-07-27 |
hxxp://42.230.44.235:53498/bin.sh | online | malware_download | 2026-07-27 |
hxxp://110.37.14.156:55942/i | online | malware_download | 2026-07-27 |
hxxp://110.37.53.25:36181/i | online | malware_download | 2026-07-27 |
hxxp://110.37.68.65:46243/i | online | malware_download | 2026-07-27 |
hxxp://182.126.120.131:56874/i | online | malware_download | 2026-07-27 |
hxxp://42.230.44.235:53498/i | online | malware_download | 2026-07-27 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: Mozi
let malicious_domains = dynamic(["182.126.120.131", "110.37.53.25", "110.37.14.156", "222.134.164.39", "115.56.149.89", "110.37.68.65", "42.230.44.235"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["182.126.120.131", "110.37.53.25", "110.37.14.156", "222.134.164.39", "115.56.149.89", "110.37.68.65", "42.230.44.235"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are 5 specific false positive scenarios for the URLhaus: Mozi Malicious URLs detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Automated Security Scanner Traffic
Scenario: Scheduled Backup and Sync Operations
Veeam.Backup.Service.exe, azcopy.exe) combined with a time-based filter to ignore alerts occurring outside of business hours if the job is known to run at night.Scenario: Endpoint Protection Quarantine and Analysis