search
Mozi botnet
Trends
- 1China Unicom IP flagged for Mozi malware distribution●IP 125.41.211.84 (China Unicom) is flagged for Mozi malware distribution, low confidence but worth a look in your logs.
A cybersecurity researcher has flagged IP address 125.41.211.84, registered to China Unicom, as a suspected source of Mozi malware distribution. The attribution is low confidence, but admins are advised to check their logs for contact with the address. Mozi is a botnet malware that primarily targets IoT devices such as routers and DVRs, often recruiting them for further attacks.
- 2IP address flagged for links to Mozi botnet malware●185.137.62.72 flagged for malware distribution linked to Mozi (MIPS/ELF), tracked by one feed, low confidence. If tied t
IP address 185.137.62.72 has been flagged by a single threat feed for malware distribution associated with the Mozi botnet, which targets MIPS-based devices using ELF binaries. The flag carries low confidence, and security observers note the address could be a Tor or VPN exit node rather than a confirmed malicious host. Network defenders are being urged to review their logs before acting on the indicator.