logo

Payload — Technical Analysis (ESXI)

ID: ad867881-f0c3-439a-a760-dd3033217361

STIX ID: report--ad867881-f0c3-439a-a760-dd3033217361

Threat Score

80/100

Uploaded: 2026-06-10

Created by: dogesec

TLP:CLEAR
...
...
This reverse-engineered report analyzes an ESXi-targeting ransomware binary (“Payload”) that parses /etc/vmware/hostd/vmInventory.xml to locate VM datastores, selectively encrypts files larger than 5 GB using per-file X25519-derived stream keys (Salsa20/ChaCha20), appends RC4-protected metadata and a ".xx0001" extension, deploys a ransom note to the ESXi web UI, and includes IOCs (SHA-256/MD5, Onion sites, file paths) and MITRE ATT&CK mappings.