Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Play Ransomware

128
Global rank
79 infographic chevron month
Month rank
172 infographic chevron week
Week rank
0
IOCs

Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.

Ransomware
Type
Unknown
Origin
1 March, 2022
First seen
6 August, 2026
Last seen
Also known as
PlayCrypt

How to analyze Play Ransomware with ANY.RUN

Type
Unknown
Origin
1 March, 2022
First seen
6 August, 2026
Last seen

IOCs

IP addresses
172.67.189.43
104.21.9.69
216.239.35.0
216.239.35.8
216.239.35.4
192.178.183.94
216.239.35.12
142.251.157.119
142.251.168.81
142.251.152.119
142.251.150.119
142.251.154.119
142.251.153.119
18.67.13.27
3.174.46.123
150.171.28.10
34.246.247.106
20.83.133.193
142.251.127.84
212.217.29.163
Hashes
efa79ab3d240c1c148a697f32b80148937c46dbcaf8ede65f383fe91030190eb
adba2b353770c06486f91688c76ac490becb2c9e4c04051325bb439495c471b4
fcee2835abe5eb5888713dc199a0ee3d2d1189583492ded08609a99e3372f7e8
6aa75841ceb93068323496e1dc84e80787409ddc0f138042d9956dc1a4847eaa
4f1dd42d2770aeb71f82fff92825458a0b1724e22945adcc8616b90bb1f31c92
5a4bb716657f62829c0140358bf7e0c7f8b7fd5e9ce8a2e5ada0221db966b9cf
7dd537f934f0b31e806f1d8c7536552d369ef2f65c4a19a6768101bae57748a4
76529b65750e04390ddaf1d9def8b762fdac895f1f67ccec946eb27575bfe097
2fab7527127a4f9e4e8d85a328a5d7b0597a2841e6381bcd7ab7983262bf387c
8725c436aadc9618e3d20bd4034bfed1d409a98ebc75aec7c8dca0863294b056
e4068e5bfe996a923b6774e7f4b1835799bcdc3fa25c979a1694591e12cac234
0c92f2b800537cd9d3fcffab10f106f8d93d4c6a285a21b00b0a06b613161351
ab7d30ab187d400cc9218a65140a771387f029314db481a72b140808733e876e
0eeee7bbdb6eb2f0ce2f4859fd1be02c460b026f45c4c12aad2a5edd92fdf5c1
681989f81f4bd054399fcb6e63e6776941125e79a0ec9e253ce7a54ad1da6d83
b8c5bf2f80790d4abbe7fd5dca0bcf5c3eeaa4e23b1b35c8854a3fdb5c26b1e9
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
61542d98ed9bf73924caedf28d3b5b33c8458401e5b44d80fc967d2802633bea
09bc2b1be8537d0f40428576a907c7d12d995a80db516ae9a7c6a19d95a7f3af
414bb3d5542d2cda46274e4ffbea3b27abb31f3d260244f078e2656507e018ba
Domains
time.android.com
wswswswsydl.hloon.sbs
connectivitycheck.gstatic.com
staging-remoteprovisioning.sandbox.googleapis.com
google.com
www.google.com
firebaseinstallations.googleapis.com
x.clarity.ms
tagging.wetransfer.com
cdn.wetransfer.com
bat.bing.com
www.bmcedirect.ma
www.clarity.ms
c.bing.com
wsssa1.hloon.sbs
edgedl.me.gvt1.com
wetransfer.zendesk.com
static.zdassets.com
accounts.google.com
nolan.wetransfer.net
URLs
http://connectivitycheck.gstatic.com/generate_204
http://wswswswsydl.hloon.sbs/
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn9am1kwbilsty737uqfy7il3g3bfcm_6yhu=&request_id=5a088820-7b5f-4454-aa4d-9631d05cb863
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn9ajtzqbilstyzxs2fq0cxwydjzpllsji4u=&request_id=1893a808-1710-4ad4-b144-3a3c68ab1080
http://www.google.com/gen_204
http://clients2.google.com/time/1/current?cup2key=9:pf_lhznlvjceiuw-1tfmh00pif7b_khbgsi28okwx_4&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://we.tl/t-q1wagrfjbdbkmaam
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&laf=b64bin&json=standard
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn88squabilsty3pmha_3oy3hejuk55ovda4=&request_id=a9791f8e-097c-4150-8aee-f843105a53f0
https://wetransfer.com/downloads/33e8a8205cba8277c92e381c9a5869ed20260804234448/555556?t_exp=1786146288&t_lsid=bb0a21c4-a7a3-4856-9969-31fe0eb8b4c8&t_network=link&t_rid=z29vz2xllw9hdxromnwxmdm0otu3mjy0mdy4mdgwmja0ntu=&t_s=download_link&t_ts=1785887088
https://cdn.wetransfer.com/_next/static/chunks/0upm7txdyrg0s.css
https://cdn.wetransfer.com/_next/static/chunks/22uc4p-ktsw3g.css
https://cdn.wetransfer.com/_next/static/chunks/2f_wiywhdfvql.css
https://cdn.wetransfer.com/_next/static/chunks/3np_qg4_pwgb7.css
https://cdn.wetransfer.com/_next/static/chunks/3zpbst-42pmec.css
https://cdn.wetransfer.com/_next/static/chunks/1cebqymduoaig.css
https://cdn.wetransfer.com/_next/static/chunks/2f8i-gxfojpxi.css
https://cdn.wetransfer.com/_next/static/chunks/2sf2na7vkb3rz.css
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4905
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 11329
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 13623
comments 0

What is Play ransomware?

Play aka PlayCrypt is relatively new yet already notorious ransomware group active since mid-2022. It has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe.

It is based on double extortion technique and has intermittent encryption as its signature feature. Partial encryption is completed much faster, besides, it prevents detection by security solutions that monitor files for extensive modifications.

It infiltrates the targeted system by exploiting vulnerabilities in public-facing applications, such as Microsoft Exchange Server. It is also distributed via phishing emails containing malicious attachments or links. Malicious ads and compromised websites has also been detected as distribution vehicles.

Play Ransomware ransom note in the ANY.RUN Sandbox Play Ransomware ransom note shown in the ANY.RUN sandbox

To move laterally within the network and deploy the ransomware payload, it abuses the legitimate tools and built-in system utilities (e.g., PowerShell, PsExec, Cobalt Strike).

After exfiltrating sensitive data, the ransomware encrypts files, adds the .play extension, and leaves a ransom note in each affected directory containing instructions on how to pay the ransom.

Play ransomware uses anti-analysis techniques to evade detection by security software, creates scheduled tasks and modifies registry entries to maintain persistence.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Play ransomware technical details

Play Ransomware is equipped with advanced capabilities focused on maximizing impact on the victims’ infrastructure:

  • Double Extortion: Data encryption and theft for increased ransom leverage.
  • Partial File Encryption: Evades detection, speeds encryption by encrypting file portions rather than entire files.
  • Security Disabling: Disables security systems to facilitate encryption and maintain persistence.
  • Log Removal: Removes system logs to obscure activity and hinder forensics.
  • Lateral Movement: Spreads within networks, increasing attack scope and leverage.
  • Network Reconnaissance: Uses NetScan for network topology and target identification to enable lateral movement.
  • Credential Dumping: Employs Mimikatz for credential extraction to facilitate privilege escalation and lateral movement.
  • Privilege Escalation: Leverages publicly available Windows Privilege Escalation Awesome Scripts for privilege escalation, enabling system-level access.
  • Remote Control: Utilizes AnyDesk and Cobalt Strike for persistent remote access, command execution, and potential data exfiltration.

Play execution process

Let’s upload the Play Ransomware to ANY.RUN’s Interactive Sandbox for analysis to see how it operates.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware analysis session in the ANY.RUN sandbox

A typical Play ransomware attack begins with gaining initial access to the victim’s network via exploiting public-facing applications or abusing valid accounts.

Once inside the targeted environment, the malware focuses on stealth by heavily relying on Living Off the Land Binaries (LOLBins). To facilitate lateral movement and execute files, Play may use command-and-control applications like Cobalt Strike or SystemBC.

Play Ransomware analysis in the ANY.RUN Sandbox Play Ransomware process analysis in the ANY.RUN sandbox

Before encrypting files, Play ransomware operators exfiltrate data. They do this by splitting compromised data into segments, compressing files, and transferring them to actor-controlled accounts.

After exfiltration, the ransomware encrypts files using an AES-RSA hybrid approach with intermittent encryption while skipping system files.

Encrypted files are appended with the .play extension, and a ransom note named ReadMe.txt is placed in the file directory on the C:\ partition.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Collect Cyber Threat Intelligence on Play Ransomware

To get the most current information about Play Ransomware, use Threat Intelligence Lookup. It contains data extracted from millions of public malware analyses conducted in ANY.RUN’s Interactive Sandbox.

You can use over 40 different search parameters, including specific IPs, domains, file names, or even mutexes. Using these filters, you can quickly gather important details about threats like Play Ransomware.

For example, if you were investigating Play Ransomware, you could start by directly searching for its name within the Threat Intelligence Lookup. Or, if you had other clues like unique file codes (hashes) or website connections it uses, you could search with those instead.

Play Ransomware search results in TI Lookup Search results for Play Ransomware in TI Lookup

A simple and effective search would be to use the search term: threatName:"Play". This type of search will show you a list of sandbox reports associated with Play Ransomware. You can then explore these reports to get a deep understanding of exactly how this ransomware works and what it does.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Play distribution methods

Play Ransomware commonly gains initial access through several attack vectors. Compromised Remote Desktop Protocol (RDP) servers are a frequent entry point, often due to weak security configurations. Attackers exploit known vulnerabilities like CVE-2020-12812 in RDP services to bypass authentication and gain unauthorized system access.

Another prevalent method involves exploiting CVE-2022-41040, the ProxyNotShell vulnerability in Microsoft Exchange, allowing for remote code execution directly on vulnerable servers.

Conclusion

Play Ransomware poses a serious risk to organizations. Its blend of advanced techniques, such as partial encryption and lateral movement, coupled with readily exploitable entry points like RDP and VPN vulnerabilities, requires comprehensive security attention.

To prevent Play Ransomware infections, organizations can analyze suspicious files and URLs in ANY.RUN's Interactive Sandbox. The service provides fast insights into the malicious behavior and allows users to manually engage with threats in a safe environment just like on a standard computer.

Sign up for a free ANY.RUN account

HAVE A LOOK AT

WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More
Emmenhtal screenshot
Emmenhtal
emmenhtal
First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More