PULSE NAME
CLOP RANSOMWARE: DISSECTING NETWORK
WHITE PetrP.73 2025-11-06 Modified: 2025-12-06
22
IOCs
MEDIUM VOLUME
Clop ransomware, operating since early 2019, has infiltrated a range of corporate and private networks, with estimated extortion profits exceeding $500 million. Originating from a group believed to be based in Russia, Clop avoids targeting Commonwealth of Independent States (CIS) countries. This ransomware variant is considered a successor to CryptoMix ransomware, which emerged in 2016. A notable technical aspect of Clop's operations includes the exploitation of vulnerabilities such as CVE-2025-61882, an Oracle E-Business Suite zero-day exploit that came to light in June 2025. This specific attack method underscores Clop's sophisticated approach to leveraging emerging CVEs for network infiltration. Analysis of Clop's network reveals a trend in IP usage, with Germany, Brazil, Panama, and Hong Kong being prominent sources. Out of 96 identified IPs associated with Clop, 41 subnet IPs have been reused, indicating a systematic approach to infrastructure.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
CryptoMix Clop
Indicators of Compromise (22)
All URL FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
URL http://198.199.74.207:1234/update.jsp 2025-11-06
URL http://5.188.206.76:8000/se1.dll 2025-11-06
FileHash-SHA256 1234387dc20796ac8142d46b173bc635339c5041e2b108ca07274a90cc512268 2025-11-06
FileHash-SHA256 2c0c80c66246d13871f05b663d42767b0e7511df9ab18c26d3504b0ae80b2045 2025-11-06
FileHash-SHA256 43c8923f1ed3fcac411db874e2facc611254be1def53d72638321ed57663588a 2025-11-06
FileHash-SHA256 5cce1b8f04cb3766b2d70738ad35c5d8b0ef1e802f193baccc5058478e9859a3 2025-11-06
FileHash-SHA256 678266acbbb36795e41a210f15e25af212a2e65f34c282cb52c023ba55e164d5 2025-11-06
FileHash-SHA256 6877d8531901040aedfc7dc3d9af121bf1800c66c8960a60cc3fd4c361135869 2025-11-06
FileHash-SHA256 7b04ac63dc41d61d409b936d2fdce47c255461f0d1d5ae86a9ddecd39e964548 2025-11-06
FileHash-SHA256 8c614d8111aca771e32ed304b9253992c5c7c8faa5b62c9141aaca595f061df3 2025-11-06
FileHash-SHA256 aa6d071d787ea8e8d054f7a699301f732cf73552d1df09a0155a5307b43df293 2025-11-06
FileHash-SHA256 b1eff60fe6c57a5a4d1136b7d2c711d058aae6d0242ba4aa1a00c3027cbdca09 2025-11-06
FileHash-SHA256 bd613b3be57f18c3bceb0aaf86a28ad8b6df7f9bccacf58044f1068d1787f8a5 2025-11-06
FileHash-SHA256 f95812cbb46f0a664a8f2200592369b105d17dfe8255054963aac4e2df53df51 2025-11-06
URL http://200.107.207.15/37: 2025-11-06
domain cl-leaks.com 2025-11-06
domain goto-pay.com 2025-11-06
domain he1p-center.com 2025-11-06
domain he1p-me.com 2025-11-06
domain in2pay.com 2025-11-06
domain pubstorm.com 2025-11-06
domain pubstorm.net 2025-11-06