DECODING GRIXBA — A PLAY RANSOMWARE SCANNER
ID: 7f7f24eb-f0b5-56f7-9e9d-afd536733418
STIX ID: report--7f7f24eb-f0b5-56f7-9e9d-afd536733418
Feed Name: THE RAVEN FILE
Threat Score
Play Ransomware's in-house infostealer 'Grixba' (four samples across 26 months) performs broad host and credential reconnaissance prior to encryption; the report documents version-specific features (v1 → v1.5 → v2 → v3), IOCs (hashes, drop path, mutex, PIA VPN IP), persistent behaviors (WMI/WinRM enumeration, event log clearing), detection/evasion trade-offs, and operational weaknesses defenders can exploit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
