Vexday analysis
Play é um grupo de ransomware ativo desde pelo menos 2022, responsável pela implantação do ransomware Playcrypt contra organizações dos setores empresarial, governamental, de infraestrutura crítica, saúde e mídia na América do Norte, América do Sul e Europa. O grupo adota o modelo de dupla extorsão, exfiltrando dados antes de criptografar os sistemas das vítimas, e é classificado por pesquisadores de segurança como uma operação fechada. Catalogado no MITRE ATT&CK sob o identificador G1040, o Play possui 26 técnicas documentadas e 6 CVEs atribuídas à sua atuação.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 26
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities 6
CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.
Impact and victims
The group Play has 1 known ransomware victims. See the most affected sectors and countries and recent victims.
Known infrastructure 2887
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
104.143.204.78:8443Cobalt Strikethreatfox156.239.4.189:50050Cobalt Strikethreatfoxaaed196675895fcb5816edf09b0cb120Cobalt Strikethreatfox153.80.242.105:8080Cobalt Strikethreatfox153.80.242.105:443Cobalt Strikethreatfox153.80.242.105:80Cobalt Strikethreatfox47.114.83.19:8084Cobalt Strikethreatfox153.80.242.105:9999Cobalt Strikethreatfox95.217.135.208:8443Cobalt Strikethreatfox46.19.140.50:8080Cobalt Strikethreatfox46.19.140.50:443Cobalt Strikethreatfox46.19.140.50:80Cobalt Strikethreatfox46.19.140.50:22Cobalt Strikethreatfox104.143.204.78:8080Cobalt Strikethreatfox104.143.204.78:443Cobalt Strikethreatfox104.143.204.78:80Cobalt Strikethreatfox104.143.204.78:22Cobalt Strikethreatfox114.215.184.158:1099Cobalt Strikethreatfox95.217.135.208:8080Cobalt Strikethreatfox114.215.184.158:22Cobalt Strikethreatfox95.217.135.208:80Cobalt Strikethreatfox95.217.135.208:443Cobalt Strikethreatfox95.217.135.208:22Cobalt Strikethreatfox156.239.4.189:8889Cobalt Strikethreatfox114.66.27.110:8434Cobalt Strikethreatfox101.35.217.145:50050Cobalt Strikethreatfox121.127.33.186:8080Cobalt Strikethreatfox121.127.33.186:80Cobalt Strikethreatfox121.127.33.186:443Cobalt Strikethreatfox121.127.33.186:22Cobalt Strikethreatfox+2887 indicators in total. See them all on the IOCs page.
Play uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →