Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Play Ransomware

128
Global rank
161 infographic chevron month
Month rank
173 infographic chevron week
Week rank
0
IOCs

Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.

Ransomware
Type
Unknown
Origin
1 March, 2022
First seen
4 September, 2026
Last seen
Also known as
PlayCrypt

How to analyze Play Ransomware with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
4 September, 2026
Last seen

IOCs

IP addresses
88.221.169.205
172.211.123.249
74.178.76.128
48.209.138.189
48.209.138.168
74.178.240.51
23.59.18.102
20.190.160.66
23.11.41.157
48.192.1.64
48.209.6.48
48.209.133.15
2.16.164.11
172.211.123.248
172.67.189.43
104.21.9.69
216.239.35.0
216.239.35.8
216.239.35.4
192.178.183.94
Hashes
137af1583253161b61f99226ef708475f312772eed4386a124c0e9e7ad88bb8d
631f5ee7bb2275402865d9a4fdf0bbab37cd9c575d884f6f0f5f5b32d04bd4c4
5ba0799ff4ff48ad4e9e60e861f84b9893156a234ee1ff927ad0e301403adc11
8be1b54a555545f93e22a531e334cdfc479803fdacdd1180bd36ea95e7ede43d
ce06ecd5b8e2a10ffb45407d6aa63b9d82393f9ce7cbd432732f4c880fbb934b
762c0439a869c19b8d5b7889abd2a0a81593bccb8096670df2452fd7ca1dd90c
abf9cffbe7cab534639dbca4c6835df5d2b68b0c3eb68da458a1a80771afba65
a9033f77395e30ff153e91bd992c076ada2585575e399d8912d6bb64880e79e0
dec9a0dafb02a75d026aa1b616f53804f2cc07ea28fe3a3eb743d0acd449ada4
b61dcaf3948dfad2bc76f46ed6dd83581e969bec053871ea86e7e5517cd045a2
ce7734d91212bf66d08a55725ff7448ca4b2a8f6b9e566ae43a2c874031747cb
2cf9709fc9cdf475e22c7a47215d6d9ad7105f33cc1f8b62b48d89d070ec816f
eafe4edca2e1f1eb142708bb2eb18d0dd889d05194176f1839a5a6a751cef977
fd40a0cbf1a28275ddd50f54d44b2562c92bdb2fff2d4c903a2c883911d43e19
6e039a9f77384db4f3d696a9c7f54bcb00cb9e4cab768e41b7f1e5f4e7f61acd
e1440d990ea6b098bedb7c18f9bbecce176102523c66960cdf73e807518586bf
722ba0650b40bcf30ced40aaec24c370b24f23b07774187e884fc95fc1fcbe39
006594b1ccf50c8df06f65761b582e9963e83a57a74733bfc3493b25143f09cc
200f36a3ed2988d94452eb7fd083a12c10cb622951463a037e260f668c155314
204e887f2016f91b74dccab0bacf8df8e5a30dd846c1476a73e5af2bdc0a210f
Domains
settings-win.data.microsoft.com
activation-v2.sls.microsoft.com
crl.microsoft.com
self.events.data.microsoft.com
ocsp.digicert.com
www.microsoft.com
client.wns.windows.com
google.com
nexusrules.officeapps.live.com
login.live.com
slscr.update.microsoft.com
fe3cr.delivery.mp.microsoft.com
go.microsoft.com
time.android.com
wswswswsydl.hloon.sbs
connectivitycheck.gstatic.com
staging-remoteprovisioning.sandbox.googleapis.com
www.google.com
firebaseinstallations.googleapis.com
x.clarity.ms
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://login.live.com/rst2.srf
http://connectivitycheck.gstatic.com/generate_204
http://wswswswsydl.hloon.sbs/
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn9am1kwbilsty737uqfy7il3g3bfcm_6yhu=&request_id=5a088820-7b5f-4454-aa4d-9631d05cb863
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn9ajtzqbilstyzxs2fq0cxwydjzpllsji4u=&request_id=1893a808-1710-4ad4-b144-3a3c68ab1080
http://www.google.com/gen_204
http://clients2.google.com/time/1/current?cup2key=9:pf_lhznlvjceiuw-1tfmh00pif7b_khbgsi28okwx_4&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://we.tl/t-q1wagrfjbdbkmaam
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&laf=b64bin&json=standard
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn88squabilsty3pmha_3oy3hejuk55ovda4=&request_id=a9791f8e-097c-4150-8aee-f843105a53f0
https://wetransfer.com/downloads/33e8a8205cba8277c92e381c9a5869ed20260804234448/555556?t_exp=1786146288&t_lsid=bb0a21c4-a7a3-4856-9969-31fe0eb8b4c8&t_network=link&t_rid=z29vz2xllw9hdxromnwxmdm0otu3mjy0mdy4mdgwmja0ntu=&t_s=download_link&t_ts=1785887088
https://cdn.wetransfer.com/_next/static/chunks/0upm7txdyrg0s.css
https://cdn.wetransfer.com/_next/static/chunks/22uc4p-ktsw3g.css
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4744
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9543
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11471
comments 0

What is Play ransomware?

Play aka PlayCrypt is relatively new yet already notorious ransomware group active since mid-2022. It has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe.

It is based on double extortion technique and has intermittent encryption as its signature feature. Partial encryption is completed much faster, besides, it prevents detection by security solutions that monitor files for extensive modifications.

It infiltrates the targeted system by exploiting vulnerabilities in public-facing applications, such as Microsoft Exchange Server. It is also distributed via phishing emails containing malicious attachments or links. Malicious ads and compromised websites has also been detected as distribution vehicles.

Play Ransomware ransom note in the ANY.RUN Sandbox Play Ransomware ransom note shown in the ANY.RUN sandbox

To move laterally within the network and deploy the ransomware payload, it abuses the legitimate tools and built-in system utilities (e.g., PowerShell, PsExec, Cobalt Strike).

After exfiltrating sensitive data, the ransomware encrypts files, adds the .play extension, and leaves a ransom note in each affected directory containing instructions on how to pay the ransom.

Play ransomware uses anti-analysis techniques to evade detection by security software, creates scheduled tasks and modifies registry entries to maintain persistence.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Play ransomware technical details

Play Ransomware is equipped with advanced capabilities focused on maximizing impact on the victims’ infrastructure:

  • Double Extortion: Data encryption and theft for increased ransom leverage.
  • Partial File Encryption: Evades detection, speeds encryption by encrypting file portions rather than entire files.
  • Security Disabling: Disables security systems to facilitate encryption and maintain persistence.
  • Log Removal: Removes system logs to obscure activity and hinder forensics.
  • Lateral Movement: Spreads within networks, increasing attack scope and leverage.
  • Network Reconnaissance: Uses NetScan for network topology and target identification to enable lateral movement.
  • Credential Dumping: Employs Mimikatz for credential extraction to facilitate privilege escalation and lateral movement.
  • Privilege Escalation: Leverages publicly available Windows Privilege Escalation Awesome Scripts for privilege escalation, enabling system-level access.
  • Remote Control: Utilizes AnyDesk and Cobalt Strike for persistent remote access, command execution, and potential data exfiltration.

Play execution process

Let’s upload the Play Ransomware to ANY.RUN’s Interactive Sandbox for analysis to see how it operates.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware analysis session in the ANY.RUN sandbox

A typical Play ransomware attack begins with gaining initial access to the victim’s network via exploiting public-facing applications or abusing valid accounts.

Once inside the targeted environment, the malware focuses on stealth by heavily relying on Living Off the Land Binaries (LOLBins). To facilitate lateral movement and execute files, Play may use command-and-control applications like Cobalt Strike or SystemBC.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware process analysis in the ANY.RUN sandbox

Before encrypting files, Play ransomware operators exfiltrate data. They do this by splitting compromised data into segments, compressing files, and transferring them to actor-controlled accounts.

After exfiltration, the ransomware encrypts files using an AES-RSA hybrid approach with intermittent encryption while skipping system files.

Encrypted files are appended with the .play extension, and a ransom note named ReadMe.txt is placed in the file directory on the C:\ partition.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Collect Cyber Threat Intelligence on Play Ransomware

To get the most current information about Play Ransomware, use Threat Intelligence Lookup. It contains data extracted from millions of public malware analyses conducted in ANY.RUN’s Interactive Sandbox.

You can use over 40 different search parameters, including specific IPs, domains, file names, or even mutexes. Using these filters, you can quickly gather important details about threats like Play Ransomware.

For example, if you were investigating Play Ransomware, you could start by directly searching for its name within the Threat Intelligence Lookup. Or, if you had other clues like unique file codes (hashes) or website connections it uses, you could search with those instead.

Play Ransomware search results in TI Lookup Search results for Play Ransomware in TI Lookup

A simple and effective search would be to use the search term: threatName:"Play". This type of search will show you a list of sandbox reports associated with Play Ransomware. You can then explore these reports to get a deep understanding of exactly how this ransomware works and what it does.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Play distribution methods

Play Ransomware commonly gains initial access through several attack vectors. Compromised Remote Desktop Protocol (RDP) servers are a frequent entry point, often due to weak security configurations. Attackers exploit known vulnerabilities like CVE-2020-12812 in RDP services to bypass authentication and gain unauthorized system access.

Another prevalent method involves exploiting CVE-2022-41040, the ProxyNotShell vulnerability in Microsoft Exchange, allowing for remote code execution directly on vulnerable servers.

Conclusion

Play Ransomware poses a serious risk to organizations. Its blend of advanced techniques, such as partial encryption and lateral movement, coupled with readily exploitable entry points like RDP and VPN vulnerabilities, requires comprehensive security attention.

To prevent Play Ransomware infections, organizations can analyze suspicious files and URLs in ANY.RUN's Interactive Sandbox. The service provides fast insights into the malicious behavior and allows users to manually engage with threats in a safe environment just like on a standard computer.

Sign up for a free ANY.RUN account

HAVE A LOOK AT

BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More
Lynx screenshot
Lynx
lynx
Lynx is a double extortion ransomware: attackers encrypt important and sensitive data and demand a ransom for decryption simultaneously threatening to publish or sell the data. Active since mid-2024. Among techniques are terminating processes and services, privilege escalation, deleting shadow copies. Distribution by phishing, malvertising, exploiting vulnerabilities.
Read More