logo

CLOP RANSOMWARE: DISSECTING NETWORK

ID: 35881748-3d90-5878-b5b0-cf89d039754e

STIX ID: report--35881748-3d90-5878-b5b0-cf89d039754e

Feed Name: THE RAVEN FILE

Threat Score
85/100

Date Published: 2025-11-04

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

This report analyzes the network infrastructure, IPs, and fingerprints associated with the Cl0p (Clop) ransomware group, linking a CVE-2025-61882 Oracle E-Business Suite zero-day exploitation to previously observed 2023 campaigns (MOVEit and GoAnywhere). The author enumerates 96 related hosts for a key fingerprint, identifies 37 high-confidence Cl0p IPs, highlights commonly reused subnets and ASNs (including notable providers), and recommends monitoring/greylisting and real-time observation rather than blunt blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.