CLOP RANSOMWARE: DISSECTING NETWORK
ID: 35881748-3d90-5878-b5b0-cf89d039754e
STIX ID: report--35881748-3d90-5878-b5b0-cf89d039754e
Feed Name: THE RAVEN FILE
This report analyzes the network infrastructure, IPs, and fingerprints associated with the Cl0p (Clop) ransomware group, linking a CVE-2025-61882 Oracle E-Business Suite zero-day exploitation to previously observed 2023 campaigns (MOVEit and GoAnywhere). The author enumerates 96 related hosts for a key fingerprint, identifies 37 high-confidence Cl0p IPs, highlights commonly reused subnets and ASNs (including notable providers), and recommends monitoring/greylisting and real-time observation rather than blunt blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
