EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

#StopRansomware: Play Ransomware

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Play. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory #StopRansomware: Play Ransomware Last Revised June 04, 2025 Alert Code AA23-352A Related topics: Cyber Threats and Response , Malware, Phishing, and Ransomware , Cybersecurity Best Practices Summary Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. Note: Updates to this advisory, originally published December 18, 2023, include: June 4, 2025: The advisory was updated to reflect new TTPs employed by Play ransomware group, as well as provide current IOCs/remove outdated IOCs for effective threat hunting. Update June 4, 2025: The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) are releasing this joint advisory to disseminate the Play ransomware group’s IOCs and TTPs identified through FBI investigations as recently as January 2025. End Update Since June 2022, the Play (also known as Playcrypt) ransomware group has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe. Play ransomware was among the most active ransomware groups in 2024. Organizations should take the following actions today to mitigate cyber threats from Play ransomware: Prioritize remediating known exploited vulnerabilities.

Indicatori CISA verificabili

53 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 2 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T07:02:10.345251+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
SHA-256372f7b45a141bb0709d578bc716cbca03104258822c4290ccbeb600223850158
SHA-256511f63455ca4f83b0347b65dda17585ad02591a9f23d8e234e5ce1321aa3381a
SHA-256859165041d75fba3759c5533e324225f355c8a07b4645b984192ad6bef06db1a
SHA-256967daff362e63ff45526f585b7944488ace1bb5bb5b30fa40d56557f1c538d09
SHA-2566de8dd5757f9a3ac5e2ac28e8a77682d7a29be25c106f785a061dcf582a20dc6Hi.exe
SHA-13d86555acaa19aeddb5896071d1e3711b062edbe
MD57ae9b68a55059d38e170e698cda22ceeHRsword.exe
SHA-1f0c3f1fd5fc95611f755b161b67d2057d73f0fb8HRsword.exe
SHA-2560e408aed1acf902a9f97abf71cf0dd354024109c5d52a79054c421be35d93549HRsword.exe
SSDEEP49152:LNvuwguQfXqc6zjj0W19DmRWA2hLyIe6Fa:pguRBzjj0WTDKWAgyIEHRsword.exe
MD51dfac999ed2123e31e85674196ae9513GRB_NET.exe
SHA-13878917397c055dcd0999ac681c9c7a83cba0f78GRB_NET.exe
SHA-256c59f3c8d61d940b56436c14bc148c1fe98862921b8f7bad97fbc96b31d71193cGRB_NET.exe
SSDEEP3072:8huRNfpfCrIWmawItD5jXROpSwm53Ag1MO/SsbdE9Z/G9rchZeWsFweKZ/Ir:8cRNJCrlLDt8pSwmnMO/Ssbie9c02eTGRB_NET.exe
MD5033c9f28acadaaa32d947a4026020beafThe9C.exe
SHA-148c62ced29bfbdf25b60c692c9b2b9396c895ee3fThe9C.exe
SHA-25690040340ee101cac7831d7035230ac8ad4224d432e5636f34f13aa1c4a0c2041fThe9C.exe
SSDEEP12288:kf+BP7MsT9RIOE0N5j48e1w6gRje1zsCXKFWl0FnNyQ:BBP4sTI0N5jxe1DgRjedsCa8WFn4QfThe9C.exe
MD530040c652389249374528ea6887ce012Gt_net.exe
SHA-13890272563cd044761a9a5c0ab049a2117b38884Gt_net.exe
SHA-25675b525b220169f07aecfb3b1991702fbd9a1e170caf0040d1fcb07c3e819f54aGt_net.exe
SSDEEP384:dxECYQed69MJPkXn+NSU0CwW6Da21oQ0gCdbUbN3cSJ83Ywsn1jDkmfcZOrY1DyV:ICBYLM3+Nl0CVbQ7mUJ3qowsl9/Gt_net.exe
MD578e4bf5353107ea0c2779333300d1ed0SVCHost.dll
SHA-18765cc8cba689398cf6487101ecfcd901f153378SVCHost.dll
SHA-25647b7b2dd88959cd7224a5542ae8d5bce928bfc986bf0d0321532a7515c244a1eSVCHost.dll
SSDEEP6144:IwYHWo3LnIyHcSlAKxHT/It9YvqAqUjWh7xfv4dg/EBePeL1NxG/KbyVlmcfP:IHWo3EyHcSNBfilxfgTeGLk/6Om0SVCHost.dll
MD58fcb6fb21b4326466378991e42ce9865
SHA-1dd27145d9e4ec4a921b664183a9cbebee568c234
SHA-2567dea671be77a2ca5772b86cf8831b02bff0567bce6a3ae023825aa40354f8aca
SSDEEP3072:CisRnzAl7X/AZfRn6sbQ6rQ7oWYRq+bWxfMlOrFj2jA2yR4l3LCtrv7fuVfkkIko:C7zMr8Jn6qrQuINtydq5E7
MD54412f230da1a3954d5065395b512ff49
SHA-1b86f648484364d6dbd0f42b526d4f25814ff00e7
SHA-2567a42f96599df8090cf89d6e3ce4316d24c6c00e499c8557a2e09d61c00c11986
SSDEEP3072:iGY1ELTd83UFPZby2FPEkmDUDp2DHb8XmYwJrL9/Tw8aIvWvZFB:vnwUdsEPU31DWvx
MD5046d8658c6ca9df9f9a8143aeb85a559PSexesvc.exe
SHA-151d3d661774cc50bb22e62beafc4bc6029df2392PSexesvc.exe
SHA-2561409e010675bf4a40db0a845b60db3aae5b302834e80adeec884aebc55eccbf7PSexesvc.exe
SSDEEP3072:jzYhT9A4w0+6APUQyHVi8qdF/xy9UFgEGLVs4Mf3osSyO6G:IZNw0yPUQy1ib/tgLMf3rSykPSexesvc.exe
MD5513c17ab6d8ec79ea6c5e196da67722c513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-13a831bc0c30c6c330070d3065c4c7b39305a9822513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-25675404543de25513b376f097ceb383e8efb9c9b95da8945fd4aa37c7b2f226212513c17ab6d8ec79ea6c5e196da67722c.exe
SSDEEP96:PNoCMDnHFBkGNutaR/3Mnh/MM4odWLqhZAoUyLh/b9U/oo2i4glifqw:FoTH7kGsaBc/ZbdNdh9i4mBw513c17ab6d8ec79ea6c5e196da67722c.exe
MD509f341874f72a5cfcedbca707bfd1b3bGRB_NET.exe
SHA-16e8582faeaf34f63fbe0083a811bcce1aa6c31deGRB_NET.exe
SHA-256453257c3494addafb39cb6815862403e827947a1e7737eb8168cd10522465debGRB_NET.exe
SSDEEP3072:1P5s39zIYe+8UGXD5jXROpSwm53Ag1MO/SsbdE9Z/G9rchZeWsFweKZ/Ic:fyIYe+8UsDt8pSwmnMO/Ssbie9c02eTGRB_NET.exe

Provenance

Allegato ufficiale CISA · 2025-06-04T16:33:46Z

SHA-512: 9b0b480821bd234b90b2398806490ce12f200e8fec72727dc65e39349bdf49f5c06187af8748397144fef2c83583e8f00a0cce87649da6dc0f9caece5180c314

TipoIndicatore (non cliccabile)File
SHA-256e8d5ad0bf292c42a9185bb1251c7e763d16614c180071b01da742972999b95da
SHA-256e652051fe47d784f6f85dc00adca1c15a8c7a40f1e5772e6a95281d8bf3d5c74
MD58fcb6fb21b4326466378991e42ce9865
SHA-1dd27145d9e4ec4a921b664183a9cbebee568c234
SHA-2567dea671be77a2ca5772b86cf8831b02bff0567bce6a3ae023825aa40354f8aca
SSDEEP3072:CisRnzAl7X/AZfRn6sbQ6rQ7oWYRq+bWxfMlOrFj2jA2yR4l3LCtrv7fuVfkkIko:C7zMr8Jn6qrQuINtydq5E7
SHA-2567a6df63d883bbccb315986c2cfb76570335abf84fafbefce047d126b32234af8
MD54412f230da1a3954d5065395b512ff49
SHA-1b86f648484364d6dbd0f42b526d4f25814ff00e7
SHA-2567a42f96599df8090cf89d6e3ce4316d24c6c00e499c8557a2e09d61c00c11986
SSDEEP3072:iGY1ELTd83UFPZby2FPEkmDUDp2DHb8XmYwJrL9/Tw8aIvWvZFB:vnwUdsEPU31DWvx
SHA-256c59f3c8d61d940b56436c14bc148c1fe98862921b8f7bad97fbc96b31d71193c
MD5513c17ab6d8ec79ea6c5e196da67722c513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-13a831bc0c30c6c330070d3065c4c7b39305a9822513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-25675404543de25513b376f097ceb383e8efb9c9b95da8945fd4aa37c7b2f226212513c17ab6d8ec79ea6c5e196da67722c.exe
SSDEEP96:PNoCMDnHFBkGNutaR/3Mnh/MM4odWLqhZAoUyLh/b9U/oo2i4glifqw:FoTH7kGsaBc/ZbdNdh9i4mBw513c17ab6d8ec79ea6c5e196da67722c.exe
MD557bcb8cfad510109f7ddedf045e86a70zxc.exe
SHA-1e6c381859f53d0c0db9fcd30fa601ecb935b93e0zxc.exe
SHA-25647c7cee3d76106279c4c28ad1de3c833c1ba0a2ec56b0150586c7e8480ccae57zxc.exe
SSDEEP6144:1ouXuOPQveEDZShYIpQD0QYa5N2WAAHIbzAW1+SM/VxZswDWSN:KiAmEQfQpHwbzd9qZsiWSNzxc.exe
MD509f341874f72a5cfcedbca707bfd1b3b
SHA-16e8582faeaf34f63fbe0083a811bcce1aa6c31de
SHA-256453257c3494addafb39cb6815862403e827947a1e7737eb8168cd10522465deb
SSDEEP3072:1P5s39zIYe+8UGXD5jXROpSwm53Ag1MO/SsbdE9Z/G9rchZeWsFweKZ/Ic:fyIYe+8UsDt8pSwmnMO/Ssbie9c02eT

Provenance

Allegato ufficiale CISA · 2023-12-12T15:45:45Z

SHA-512: 54b6c78c7975f88a4f9c255a3fa170aa31be17a02365f235cfadd1dbfdccade60a5125d6006d0e58da331bfd099a4838508dc111ba57a316674c2f58b0bc9c45

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
04/06/2025 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1003, T1016, T1027, T1048, T1057, T1059, T1059.001, T1070, T1070.001, T1078, T1133, T1190, T1484.001, T1486, T1518, T1518.001, T1552, T1560.001, T1562.001, T1570, T1657
CVE
CVE-2018-13379, CVE-2020-12812, CVE-2022-41040, CVE-2022-41082, CVE-2024-57727
Classification
Critical
Group attributed by the source
Play
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source