Play
(Active)
Aliases
PlayCrypt
Description
This entry is under construction. However, we have included some details below.
Ransomware Type
Crypto-Ransomware
First Seen
Threat Actors
Type
Actor
Affiliate
ShadowSyndicate
Extortion Links
Moyen
Lien
TOR
http://k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion
TOR
http://mbrlkbtq5jonaqkurjwmxftytyn2ethqvbxfu4rgjbkkknndqwae6byd.onion
Extortion Types
Direct Extortion
Double Extortion
Communication
Moyen
Identifiant
Email
marinachin@gmx.de
Email
teilightomemaucd@gmx.com
Encryption
Type
Hybrid
Files
AES
Key
RSA
Additional Encryption
[intermittent encryption] every other 0x100000 bytes
File Extension
<file name>.<file extension>.play
Ransom Note Name
ReadMe.txt
Decryptors
References & Publications