s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.clop

📛 Threat Title

Malware family: Clop

Category: Clop First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.clop`. Printable name: Clop. Aliases: Cl0p.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.clop VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.clop

IOC database

Type
domain
Value
elf.clop
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.clop

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.clop

References (1)

Remediations (10)

  • web:attack.mitre.org

    Clop is a ransomware family that was first observed in February 2019 and has been used against retail, transportation and logistics, education, manufacturing, engineering, automotive, energy, financial, aerospace, telecommunications, professional and legal services, healthcare, and high tech industries.

  • web:blackpointcyber.com

    Clop (sometimes referred to as Cl0p) ransomware was first identified in 2019 and, in 2020, added the double extortion method, where victims' data is stolen and leaked via a data leak site if the ransom is not paid, to their arsenal. Clop is purportedly derived from the Cryptomix ransomware operation; it is widely believed that the group's name originates from a Russian "klop", which ...

  • web:cybelangel.com

    Cl0p, " Clop " or TA505, is a notorious ransomware group that has gained global attention for its advanced cyber extortion tactics. First observed in 2019 as a variant of the CryptoMix ransomware family , the Cl0p/ Clop ransomware gang quickly became a major threat.

  • web:en.wikipedia.org

    Clop (sometimes written " Cl0p ") is a cybercriminal organization known for its multilevel extortion techniques and global malware distribution. It has extorted more than $500 million in ransom payments, targeting major organizations worldwide.

  • web:go.cyberproof.com

    These services involve regular scanning to discover potential weaknesses, followed by prioritization and remediation steps to minimize the risk. By proactively managing vulnerabilities, businesses can enhance their security posture and protect themselves from potential cyber threats.

  • web:heimdalsecurity.com

    Clop Ransomware, belonging to the popular Cryptomix family , is a dangerous file-encrypting malware . It actively targets systems with inadequate security, encrypting files and appending the '.Clop' extension to them. The 'Clop virus' name comes from the Russian word 'klop,' which means 'bed bug.' This bug, from the Cimex family , feeds on human blood at night. This article will ...

  • web:www.cisa.gov

    In 2019, TA505 actors leveraged CL0P ransomware as the final payload of a phishing campaign involving a macro-enabled document that used a Get2 malware dropper for downloading SDBot and FlawedGrace. In recent campaigns beginning 2021, CL0P preferred to rely mostly on data exfiltration over encryption.

  • web:www.cyfirma.com

    INTRODUCTION The Cl0p group has been active since early 2019, leveraging vulnerabilities and exploits to encrypt files for ransom. The ransomware group has recently targeted 43 organizations and exfiltrated sensitive details. This report highlights the breakup of the target organizations, trends observed of Cl0p ransomware in the last six quarters, the initial access leveraged along with ...

  • web:www.picussecurity.com

    Cl0p (or Clop ) is a sophisticated ransomware variant that evolved from the CryptoMix family and first emerged in February 2019. It is frequently deployed as the final payload in attacks orchestrated by the financially motivated threat group TA505. This group uses large-scale spear-phishing campaigns and exploits zero-day vulnerabilities to compromise networks.

  • web:www.sentinelone.com

    Clop (cl0p) ransomware uses advanced malware to lock files and leak stolen data. Discover its typical targets, negotiation tactics, and how you can block it now.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.