ESXiArgs: The code behind the ransomware
ID: 97c5593b-b627-5280-9ce0-d27cb5d44092
STIX ID: report--97c5593b-b627-5280-9ce0-d27cb5d44092
Feed Name: TrustedSec blog
**Executive Summary:** This report presents a technical deep-dive into an ESXi-focused ransomware sample that drops a public.pem, uses an encrypt.sh shell script to enumerate VMFS volumes and locate VM files (VMDK, VMX, VMXF, VMSD, VMSN, VSQP, VMSS, NVRAM), launches concurrent encrypt processes, and runs an ELF encryptor which generates a random 32-byte key, RSA-encrypts that key, then encrypts file contents in 1MB+ chunks using the SOSEMANUK stream cipher; ransom notes are placed by overwriting VMware index.html and the system MOTD.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
