logo

Collecting and operationalizing threat data from the Mozi botnet

ID: 1d7fab17-e681-5512-8fab-13d50f3f5df2

STIX ID: report--1d7fab17-e681-5512-8fab-13d50f3f5df2

Feed Name: Elastic Security Labs

Threat Score
72/100

Date Published: 2022-06-02

Date Updated: 2026-04-27

...
...

This report analyzes the Mozi peer-to-peer IoT botnet: how samples were collected from ThreatFox and Malware Bazaar, how corrupted UPX-packed ARM ELF samples were repaired and unpacked, and which indicators and TTPs were extracted (network IOCs, ip:port, iptables changes, HTTP fingerprint). It demonstrates ingestion and enrichment into the Elastic Stack for visualization and hunting, provides a YARA rule to detect the UPX header zeroing obfuscation, describes propagation fingerprints useful for discovery (HTTP response headers), and gives mitigation advice (change default credentials, patch firmware, segment and limit Internet exposure).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.