Play Ransomware is active for a while, but it come under lime light when it attack the Argentina's Judiciary of Córdoba, forcing the judicial system to come to at rest. Unlike most ransomware operations that leave lengthy ransom notes Play ransom notes simple, just the name and a email address. The extension:
.play is added to the encrypted files.
Play Ransomware Signatures
Family: Ransom:Win32/PlayCrypt.PA!MTB
MD5: 223eff1610b432a1f1aa06c60bd7b9a6
SHA256: 006ae41910887f0811a3ba2868ef9576bbd265216554850112319af878f06e55
Play Ransomware Download