Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Play Ransomware

129
Global rank
164 infographic chevron month
Month rank
169 infographic chevron week
Week rank

Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.

Ransomware
Type
Unknown
Origin
1 March, 2022
First seen
4 September, 2026
Last seen
Also known as
PlayCrypt

How to analyze Play Ransomware with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
4 September, 2026
Last seen

IOCs

IP addresses
88.221.169.205
172.211.123.249
74.178.76.128
48.209.138.189
48.209.138.168
74.178.240.51
23.59.18.102
20.190.160.66
23.11.41.157
48.192.1.64
48.209.6.48
48.209.133.15
2.16.164.11
172.211.123.248
172.67.189.43
104.21.9.69
216.239.35.0
216.239.35.8
216.239.35.4
192.178.183.94
Hashes
fe6db0a68179322f2a7ab3604a0a418cce0f3cae1541018c5093207df5a31138
9357ca9cf7373079035fcb410f92cb9b82fd23865c25b9b0504fe90f0b7dcb5d
86b437ba22e40b9821b7a6d18058ec91150bb9fe7a0ce2aa33029919ba7cca1f
42b9ed9c881b4844416e45d1d225a2c8808a0ddd994c796f909e2e6f7691b993
00eff28b7ad8b8f0ffbf921db7f0bbe42a811df1c97e183249f7fc3e5f0bf46b
9eba6876fd2a2b074ee2641a3289381a58a2b8dc117cf559ad8033961a02617f
6c23d75054bf66de33f6a85e20c1ba5014c7c6440b1df73a6ed29093cdf83454
d36e681d5c6d7a369d5d38adaf25a830f41f13008de5d4f4dd67114a5d48e181
0e9bbd4c077581e3d394d80a3dba4a7cc658cbb4fc6a7073960b7c25a8bd43b0
f76ab9991ce16bcc7bcf1c5f7af1993e63157717f91b345d6fc7448ed0fe7406
2744d826d3f0a8bafe15a763e8eddb0c04fa030b0ff65f3212940e07b81c3b2e
e7f4718611af0e39790fa348a9fc698a792f4d62e69b0b9f48136a7d008c5f80
a64b72e7292c405def2bee947dbec3bf3b991eb8fd35c65c9eab86396aa2b348
fb4768a34ecdfaae4d5e18b11b79e520a24dd10ce3dceb623e18c4fd55c0dee2
c046770bfdba2e6b518bfdb210bc4832923f1732caae81a0145f2e325037afc1
217d993083cc158a15492b14219f1dccd65f2a9b4cf2ae3e04ca73897d6515c5
f211dbc5f7496533594e4a37cd912fe5149cf78d302dd2839cb3668df8275890
b75646fe6abeb5793bb14d0c6666d57d21e7769fcb6e383af8b56abc89eaf90d
7297aa9fe5152e86ac6285e9ae0339dcaee7aab14dfb45960feaca00dedfc444
2b8bdfc52835221e2593c0a91303d4156e149b3c6a94de11d60750760273355f
Domains
settings-win.data.microsoft.com
activation-v2.sls.microsoft.com
crl.microsoft.com
self.events.data.microsoft.com
ocsp.digicert.com
www.microsoft.com
client.wns.windows.com
google.com
nexusrules.officeapps.live.com
login.live.com
slscr.update.microsoft.com
fe3cr.delivery.mp.microsoft.com
go.microsoft.com
time.android.com
wswswswsydl.hloon.sbs
connectivitycheck.gstatic.com
staging-remoteprovisioning.sandbox.googleapis.com
www.google.com
firebaseinstallations.googleapis.com
x.clarity.ms
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://login.live.com/rst2.srf
http://connectivitycheck.gstatic.com/generate_204
http://wswswswsydl.hloon.sbs/
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn9am1kwbilsty737uqfy7il3g3bfcm_6yhu=&request_id=5a088820-7b5f-4454-aa4d-9631d05cb863
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn9ajtzqbilstyzxs2fq0cxwydjzpllsji4u=&request_id=1893a808-1710-4ad4-b144-3a3c68ab1080
http://www.google.com/gen_204
http://clients2.google.com/time/1/current?cup2key=9:pf_lhznlvjceiuw-1tfmh00pif7b_khbgsi28okwx_4&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://we.tl/t-q1wagrfjbdbkmaam
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&laf=b64bin&json=standard
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn88squabilsty3pmha_3oy3hejuk55ovda4=&request_id=a9791f8e-097c-4150-8aee-f843105a53f0
https://wetransfer.com/downloads/33e8a8205cba8277c92e381c9a5869ed20260804234448/555556?t_exp=1786146288&t_lsid=bb0a21c4-a7a3-4856-9969-31fe0eb8b4c8&t_network=link&t_rid=z29vz2xllw9hdxromnwxmdm0otu3mjy0mdy4mdgwmja0ntu=&t_s=download_link&t_ts=1785887088
https://cdn.wetransfer.com/_next/static/chunks/0upm7txdyrg0s.css
https://cdn.wetransfer.com/_next/static/chunks/22uc4p-ktsw3g.css
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 3785
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 4251
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 5556
comments 0

What is Play ransomware?

Play aka PlayCrypt is relatively new yet already notorious ransomware group active since mid-2022. It has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe.

It is based on double extortion technique and has intermittent encryption as its signature feature. Partial encryption is completed much faster, besides, it prevents detection by security solutions that monitor files for extensive modifications.

It infiltrates the targeted system by exploiting vulnerabilities in public-facing applications, such as Microsoft Exchange Server. It is also distributed via phishing emails containing malicious attachments or links. Malicious ads and compromised websites has also been detected as distribution vehicles.

Play Ransomware ransom note in the ANY.RUN Sandbox Play Ransomware ransom note shown in the ANY.RUN sandbox

To move laterally within the network and deploy the ransomware payload, it abuses the legitimate tools and built-in system utilities (e.g., PowerShell, PsExec, Cobalt Strike).

After exfiltrating sensitive data, the ransomware encrypts files, adds the .play extension, and leaves a ransom note in each affected directory containing instructions on how to pay the ransom.

Play ransomware uses anti-analysis techniques to evade detection by security software, creates scheduled tasks and modifies registry entries to maintain persistence.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Play ransomware technical details

Play Ransomware is equipped with advanced capabilities focused on maximizing impact on the victims’ infrastructure:

  • Double Extortion: Data encryption and theft for increased ransom leverage.
  • Partial File Encryption: Evades detection, speeds encryption by encrypting file portions rather than entire files.
  • Security Disabling: Disables security systems to facilitate encryption and maintain persistence.
  • Log Removal: Removes system logs to obscure activity and hinder forensics.
  • Lateral Movement: Spreads within networks, increasing attack scope and leverage.
  • Network Reconnaissance: Uses NetScan for network topology and target identification to enable lateral movement.
  • Credential Dumping: Employs Mimikatz for credential extraction to facilitate privilege escalation and lateral movement.
  • Privilege Escalation: Leverages publicly available Windows Privilege Escalation Awesome Scripts for privilege escalation, enabling system-level access.
  • Remote Control: Utilizes AnyDesk and Cobalt Strike for persistent remote access, command execution, and potential data exfiltration.

Play execution process

Let’s upload the Play Ransomware to ANY.RUN’s Interactive Sandbox for analysis to see how it operates.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware analysis session in the ANY.RUN sandbox

A typical Play ransomware attack begins with gaining initial access to the victim’s network via exploiting public-facing applications or abusing valid accounts.

Once inside the targeted environment, the malware focuses on stealth by heavily relying on Living Off the Land Binaries (LOLBins). To facilitate lateral movement and execute files, Play may use command-and-control applications like Cobalt Strike or SystemBC.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware process analysis in the ANY.RUN sandbox

Before encrypting files, Play ransomware operators exfiltrate data. They do this by splitting compromised data into segments, compressing files, and transferring them to actor-controlled accounts.

After exfiltration, the ransomware encrypts files using an AES-RSA hybrid approach with intermittent encryption while skipping system files.

Encrypted files are appended with the .play extension, and a ransom note named ReadMe.txt is placed in the file directory on the C:\ partition.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Collect Cyber Threat Intelligence on Play Ransomware

To get the most current information about Play Ransomware, use Threat Intelligence Lookup. It contains data extracted from millions of public malware analyses conducted in ANY.RUN’s Interactive Sandbox.

You can use over 40 different search parameters, including specific IPs, domains, file names, or even mutexes. Using these filters, you can quickly gather important details about threats like Play Ransomware.

For example, if you were investigating Play Ransomware, you could start by directly searching for its name within the Threat Intelligence Lookup. Or, if you had other clues like unique file codes (hashes) or website connections it uses, you could search with those instead.

Play Ransomware search results in TI Lookup Search results for Play Ransomware in TI Lookup

A simple and effective search would be to use the search term: threatName:"Play". This type of search will show you a list of sandbox reports associated with Play Ransomware. You can then explore these reports to get a deep understanding of exactly how this ransomware works and what it does.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Play distribution methods

Play Ransomware commonly gains initial access through several attack vectors. Compromised Remote Desktop Protocol (RDP) servers are a frequent entry point, often due to weak security configurations. Attackers exploit known vulnerabilities like CVE-2020-12812 in RDP services to bypass authentication and gain unauthorized system access.

Another prevalent method involves exploiting CVE-2022-41040, the ProxyNotShell vulnerability in Microsoft Exchange, allowing for remote code execution directly on vulnerable servers.

Conclusion

Play Ransomware poses a serious risk to organizations. Its blend of advanced techniques, such as partial encryption and lateral movement, coupled with readily exploitable entry points like RDP and VPN vulnerabilities, requires comprehensive security attention.

To prevent Play Ransomware infections, organizations can analyze suspicious files and URLs in ANY.RUN's Interactive Sandbox. The service provides fast insights into the malicious behavior and allows users to manually engage with threats in a safe environment just like on a standard computer.

Sign up for a free ANY.RUN account

HAVE A LOOK AT

DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
Phantom Stealer screenshot
Phantom Stealer
phantomstealer
Phantom Stealer is a commercially available Malware-as-a-Service infostealer targeting Windows systems. It harvests browser passwords, session cookies, payment data, cryptocurrency wallets, system information, screenshots, and application data.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
Grandoreiro screenshot
Grandoreiro
grandoreiro
Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More