This hunt targets adversary behavior involving initial access or command and control via Mozi malware-infected web resources, specifically identifying traffic to known malicious URLs associated with this threat family. Proactively hunting for these indicators in Azure Sentinel is critical because Mozi’s persistence mechanisms can silently compromise endpoints before traditional signature-based detections trigger, allowing the SOC team to isolate affected assets early in the kill chain.
Threat: Mozi Total URLs: 22 Active URLs: 20
| URL | Status | Threat | Date Added |
|---|---|---|---|
hxxp://110.36.28.183:55326/i | online | malware_download | 2026-06-30 |
hxxp://61.53.13.78:60950/i | online | malware_download | 2026-06-30 |
hxxp://123.129.131.196:36697/bin.sh | online | malware_download | 2026-06-30 |
hxxp://110.39.239.253:46466/i | online | malware_download | 2026-06-30 |
hxxp://125.43.104.215:56416/bin.sh | online | malware_download | 2026-06-30 |
hxxp://182.120.151.216:50519/i | online | malware_download | 2026-06-30 |
hxxp://110.39.239.253:46466/bin.sh | online | malware_download | 2026-06-30 |
hxxp://222.139.35.187:53691/i | online | malware_download | 2026-06-30 |
hxxp://182.120.151.216:50519/bin.sh | online | malware_download | 2026-06-30 |
hxxp://182.126.87.85:40467/i | online | malware_download | 2026-06-30 |
hxxp://123.4.151.255:49020/i | online | malware_download | 2026-06-30 |
hxxp://123.4.151.255:49020/bin.sh | online | malware_download | 2026-06-30 |
hxxp://115.55.44.88:49375/i | online | malware_download | 2026-06-30 |
hxxp://115.55.44.88:49375/bin.sh | online | malware_download | 2026-06-30 |
hxxp://203.99.183.203:53736/i | offline | malware_download | 2026-06-30 |
hxxp://182.126.126.219:56041/i | offline | malware_download | 2026-06-30 |
hxxp://123.11.8.74:44379/i | online | malware_download | 2026-06-30 |
hxxp://123.11.8.74:44379/bin.sh | online | malware_download | 2026-06-30 |
hxxp://42.229.185.49:56590/bin.sh | online | malware_download | 2026-06-30 |
hxxp://115.49.75.67:43854/i | online | malware_download | 2026-06-30 |
hxxp://222.137.5.187:58895/i | online | malware_download | 2026-06-30 |
hxxp://115.49.75.67:43854/bin.sh | online | malware_download | 2026-06-30 |
// Hunt for DNS resolution of URLhaus malicious domains
// Threat: Mozi
let malicious_domains = dynamic(["115.49.75.67", "222.137.5.187", "125.43.104.215", "110.39.239.253", "182.126.87.85", "182.120.151.216", "123.4.151.255", "42.229.185.49", "110.36.28.183", "123.11.8.74", "123.129.131.196", "61.53.13.78", "115.55.44.88", "222.139.35.187"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses
| order by TimeGenerated desc
// Hunt for web traffic to URLhaus malicious domains
let malicious_domains = dynamic(["115.49.75.67", "222.137.5.187", "125.43.104.215", "110.39.239.253", "182.126.87.85", "182.120.151.216", "123.4.151.255", "42.229.185.49", "110.36.28.183", "123.11.8.74", "123.129.131.196", "61.53.13.78", "115.55.44.88", "222.139.35.187"]);
CommonSecurityLog
| where RequestURL has_any (malicious_domains) or DestinationHostName has_any (malicious_domains)
| project TimeGenerated, SourceIP, RequestURL, DestinationHostName, DeviceAction
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the URLhaus: Mozi Malicious URLs detection rule, tailored for an enterprise environment where legitimate administrative and operational traffic may intersect with known malicious URL patterns.
Endpoint Security Agent Updates (CrowdStrike/SentinelOne)
User-Agent strings of the security agents (e.g., CrowdStrike-Falcon-* or SentinelOne-Client) and whitelist the known update server domains (e.g., *.falcon.crowdstrike.com, updates.sentinelone.net).IT Asset Management Inventory Scans
svc-lansweeper, svc-discovery) and filter out URLs containing specific internal path parameters or query strings that indicate a “redirect” or “handshake” event rather than direct user navigation.Scheduled Data Backup and Sync Jobs