EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

#StopRansomware: Play Ransomware

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Play. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory #StopRansomware: Play Ransomware Last Revised June 04, 2025 Alert Code AA23-352A Related topics: Cyber Threats and Response , Malware, Phishing, and Ransomware , Cybersecurity Best Practices Summary Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. Note: Updates to this advisory, originally published December 18, 2023, include: June 4, 2025: The advisory was updated to reflect new TTPs employed by Play ransomware group, as well as provide current IOCs/remove outdated IOCs for effective threat hunting. Update June 4, 2025: The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) are releasing this joint advisory to disseminate the Play ransomware group’s IOCs and TTPs identified through FBI investigations as recently as January 2025. End Update Since June 2022, the Play (also known as Playcrypt) ransomware group has impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe. Play ransomware was among the most active ransomware groups in 2024. Organizations should take the following actions today to mitigate cyber threats from Play ransomware: Prioritize remediating known exploited vulnerabilities.

Indicatori CISA verificabili

53 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 2 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T07:02:10.345251+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
SHA-256372f7b45a141bb0709d578bc716cbca03104258822c4290ccbeb600223850158
SHA-256511f63455ca4f83b0347b65dda17585ad02591a9f23d8e234e5ce1321aa3381a
SHA-256859165041d75fba3759c5533e324225f355c8a07b4645b984192ad6bef06db1a
SHA-256967daff362e63ff45526f585b7944488ace1bb5bb5b30fa40d56557f1c538d09
SHA-2566de8dd5757f9a3ac5e2ac28e8a77682d7a29be25c106f785a061dcf582a20dc6Hi.exe
SHA-13d86555acaa19aeddb5896071d1e3711b062edbe
MD57ae9b68a55059d38e170e698cda22ceeHRsword.exe
SHA-1f0c3f1fd5fc95611f755b161b67d2057d73f0fb8HRsword.exe
SHA-2560e408aed1acf902a9f97abf71cf0dd354024109c5d52a79054c421be35d93549HRsword.exe
SSDEEP49152:LNvuwguQfXqc6zjj0W19DmRWA2hLyIe6Fa:pguRBzjj0WTDKWAgyIEHRsword.exe
MD51dfac999ed2123e31e85674196ae9513GRB_NET.exe
SHA-13878917397c055dcd0999ac681c9c7a83cba0f78GRB_NET.exe
SHA-256c59f3c8d61d940b56436c14bc148c1fe98862921b8f7bad97fbc96b31d71193cGRB_NET.exe
SSDEEP3072:8huRNfpfCrIWmawItD5jXROpSwm53Ag1MO/SsbdE9Z/G9rchZeWsFweKZ/Ir:8cRNJCrlLDt8pSwmnMO/Ssbie9c02eTGRB_NET.exe
MD5033c9f28acadaaa32d947a4026020beafThe9C.exe
SHA-148c62ced29bfbdf25b60c692c9b2b9396c895ee3fThe9C.exe
SHA-25690040340ee101cac7831d7035230ac8ad4224d432e5636f34f13aa1c4a0c2041fThe9C.exe
SSDEEP12288:kf+BP7MsT9RIOE0N5j48e1w6gRje1zsCXKFWl0FnNyQ:BBP4sTI0N5jxe1DgRjedsCa8WFn4QfThe9C.exe
MD530040c652389249374528ea6887ce012Gt_net.exe
SHA-13890272563cd044761a9a5c0ab049a2117b38884Gt_net.exe
SHA-25675b525b220169f07aecfb3b1991702fbd9a1e170caf0040d1fcb07c3e819f54aGt_net.exe
SSDEEP384:dxECYQed69MJPkXn+NSU0CwW6Da21oQ0gCdbUbN3cSJ83Ywsn1jDkmfcZOrY1DyV:ICBYLM3+Nl0CVbQ7mUJ3qowsl9/Gt_net.exe
MD578e4bf5353107ea0c2779333300d1ed0SVCHost.dll
SHA-18765cc8cba689398cf6487101ecfcd901f153378SVCHost.dll
SHA-25647b7b2dd88959cd7224a5542ae8d5bce928bfc986bf0d0321532a7515c244a1eSVCHost.dll
SSDEEP6144:IwYHWo3LnIyHcSlAKxHT/It9YvqAqUjWh7xfv4dg/EBePeL1NxG/KbyVlmcfP:IHWo3EyHcSNBfilxfgTeGLk/6Om0SVCHost.dll
MD58fcb6fb21b4326466378991e42ce9865
SHA-1dd27145d9e4ec4a921b664183a9cbebee568c234
SHA-2567dea671be77a2ca5772b86cf8831b02bff0567bce6a3ae023825aa40354f8aca
SSDEEP3072:CisRnzAl7X/AZfRn6sbQ6rQ7oWYRq+bWxfMlOrFj2jA2yR4l3LCtrv7fuVfkkIko:C7zMr8Jn6qrQuINtydq5E7
MD54412f230da1a3954d5065395b512ff49
SHA-1b86f648484364d6dbd0f42b526d4f25814ff00e7
SHA-2567a42f96599df8090cf89d6e3ce4316d24c6c00e499c8557a2e09d61c00c11986
SSDEEP3072:iGY1ELTd83UFPZby2FPEkmDUDp2DHb8XmYwJrL9/Tw8aIvWvZFB:vnwUdsEPU31DWvx
MD5046d8658c6ca9df9f9a8143aeb85a559PSexesvc.exe
SHA-151d3d661774cc50bb22e62beafc4bc6029df2392PSexesvc.exe
SHA-2561409e010675bf4a40db0a845b60db3aae5b302834e80adeec884aebc55eccbf7PSexesvc.exe
SSDEEP3072:jzYhT9A4w0+6APUQyHVi8qdF/xy9UFgEGLVs4Mf3osSyO6G:IZNw0yPUQy1ib/tgLMf3rSykPSexesvc.exe
MD5513c17ab6d8ec79ea6c5e196da67722c513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-13a831bc0c30c6c330070d3065c4c7b39305a9822513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-25675404543de25513b376f097ceb383e8efb9c9b95da8945fd4aa37c7b2f226212513c17ab6d8ec79ea6c5e196da67722c.exe
SSDEEP96:PNoCMDnHFBkGNutaR/3Mnh/MM4odWLqhZAoUyLh/b9U/oo2i4glifqw:FoTH7kGsaBc/ZbdNdh9i4mBw513c17ab6d8ec79ea6c5e196da67722c.exe
MD509f341874f72a5cfcedbca707bfd1b3bGRB_NET.exe
SHA-16e8582faeaf34f63fbe0083a811bcce1aa6c31deGRB_NET.exe
SHA-256453257c3494addafb39cb6815862403e827947a1e7737eb8168cd10522465debGRB_NET.exe
SSDEEP3072:1P5s39zIYe+8UGXD5jXROpSwm53Ag1MO/SsbdE9Z/G9rchZeWsFweKZ/Ic:fyIYe+8UsDt8pSwmnMO/Ssbie9c02eTGRB_NET.exe

Provenienza

Allegato ufficiale CISA · 2025-06-04T16:33:46Z

SHA-512: 9b0b480821bd234b90b2398806490ce12f200e8fec72727dc65e39349bdf49f5c06187af8748397144fef2c83583e8f00a0cce87649da6dc0f9caece5180c314

TipoIndicatore (non cliccabile)File
SHA-256e8d5ad0bf292c42a9185bb1251c7e763d16614c180071b01da742972999b95da
SHA-256e652051fe47d784f6f85dc00adca1c15a8c7a40f1e5772e6a95281d8bf3d5c74
MD58fcb6fb21b4326466378991e42ce9865
SHA-1dd27145d9e4ec4a921b664183a9cbebee568c234
SHA-2567dea671be77a2ca5772b86cf8831b02bff0567bce6a3ae023825aa40354f8aca
SSDEEP3072:CisRnzAl7X/AZfRn6sbQ6rQ7oWYRq+bWxfMlOrFj2jA2yR4l3LCtrv7fuVfkkIko:C7zMr8Jn6qrQuINtydq5E7
SHA-2567a6df63d883bbccb315986c2cfb76570335abf84fafbefce047d126b32234af8
MD54412f230da1a3954d5065395b512ff49
SHA-1b86f648484364d6dbd0f42b526d4f25814ff00e7
SHA-2567a42f96599df8090cf89d6e3ce4316d24c6c00e499c8557a2e09d61c00c11986
SSDEEP3072:iGY1ELTd83UFPZby2FPEkmDUDp2DHb8XmYwJrL9/Tw8aIvWvZFB:vnwUdsEPU31DWvx
SHA-256c59f3c8d61d940b56436c14bc148c1fe98862921b8f7bad97fbc96b31d71193c
MD5513c17ab6d8ec79ea6c5e196da67722c513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-13a831bc0c30c6c330070d3065c4c7b39305a9822513c17ab6d8ec79ea6c5e196da67722c.exe
SHA-25675404543de25513b376f097ceb383e8efb9c9b95da8945fd4aa37c7b2f226212513c17ab6d8ec79ea6c5e196da67722c.exe
SSDEEP96:PNoCMDnHFBkGNutaR/3Mnh/MM4odWLqhZAoUyLh/b9U/oo2i4glifqw:FoTH7kGsaBc/ZbdNdh9i4mBw513c17ab6d8ec79ea6c5e196da67722c.exe
MD557bcb8cfad510109f7ddedf045e86a70zxc.exe
SHA-1e6c381859f53d0c0db9fcd30fa601ecb935b93e0zxc.exe
SHA-25647c7cee3d76106279c4c28ad1de3c833c1ba0a2ec56b0150586c7e8480ccae57zxc.exe
SSDEEP6144:1ouXuOPQveEDZShYIpQD0QYa5N2WAAHIbzAW1+SM/VxZswDWSN:KiAmEQfQpHwbzd9qZsiWSNzxc.exe
MD509f341874f72a5cfcedbca707bfd1b3b
SHA-16e8582faeaf34f63fbe0083a811bcce1aa6c31de
SHA-256453257c3494addafb39cb6815862403e827947a1e7737eb8168cd10522465deb
SSDEEP3072:1P5s39zIYe+8UGXD5jXROpSwm53Ag1MO/SsbdE9Z/G9rchZeWsFweKZ/Ic:fyIYe+8UsDt8pSwmnMO/Ssbie9c02eT

Provenienza

Allegato ufficiale CISA · 2023-12-12T15:45:45Z

SHA-512: 54b6c78c7975f88a4f9c255a3fa170aa31be17a02365f235cfadd1dbfdccade60a5125d6006d0e58da331bfd099a4838508dc111ba57a316674c2f58b0bc9c45

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
04/06/2025 14:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1003, T1016, T1027, T1048, T1057, T1059, T1059.001, T1070, T1070.001, T1078, T1133, T1190, T1484.001, T1486, T1518, T1518.001, T1552, T1560.001, T1562.001, T1570, T1657
CVE
CVE-2018-13379, CVE-2020-12812, CVE-2022-41040, CVE-2022-41082, CVE-2024-57727
Classificazione
Critica
Gruppo attribuito dalla fonte
Play
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale