daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

vmware-esx-vcenter.md (6616B)


      1 ---
      2 title: "VMware ESX / vCenter Pentesting"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/vmware-esx-vcenter....md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/vmware-esx-vcenter....md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # VMware ESX / vCenter Pentesting
     14 
     15 ## Enumeration
     16 
     17 ```bash
     18 nmap -sV --script "http-vmware-path-vuln or vmware-version" -p <PORT> <IP>
     19 msf> use auxiliary/scanner/vmware/esx_fingerprint
     20 msf> use auxiliary/scanner/http/ms15_034_http_sys_memory_dump
     21 ```
     22 
     23 ## Bruteforce
     24 
     25 ```bash
     26 msf> auxiliary/scanner/vmware/vmware_http_login
     27 ```
     28 
     29 If you find valid credentials, you can use more metasploit scanner modules to obtain information.
     30 
     31 ## ESXi Post-Exploitation & Ransomware Operations
     32 
     33 ### Attack Workflow inside Virtual Estates
     34 
     35 * **Develop**: maintain a lightweight management agent (e.g., *MrAgent*), encryptor (e.g., *Mario*), and leak infrastructure.
     36 * **Infiltrate**: compromise vSphere management, enumerate hosts, steal data, and stage payloads.
     37 * **Deploy**: push agents to each ESXi host, let them poll C2, and pull the encryptor when instructed.
     38 * **Extort**: leak proof-of-compromise data and run ransom chats once encryption is confirmed.<sup>[[1]](#references)</sup>
     39 
     40 ### Hypervisor Takeover Primitives
     41 
     42 Once command execution on an ESXi console/SSH session is obtained, attackers typically run the following management commands to fingerprint and isolate the host before ransomware deployment:
     43 
     44 ```bash
     45 uname -a                                   # hostname / build metadata for tracking
     46 esxcli --formatter=csv network nic list    # adapter + MAC inventory
     47 esxcli --formatter=csv network ip interface ipv4 get
     48 esxcli network firewall set --enabled false
     49 /etc/init.d/vpxa stop                      # cut vCenter off from the host
     50 passwd root                                # rotate credentials under attacker control
     51 ```
     52 
     53 The same agent usually keeps a persistent loop that polls a hard-coded C2 URI. Any unreachable status triggers retries, meaning the beacon stays live until operators push instructions.<sup>[[1]](#references)</sup>
     54 
     55 ### MrAgent-Style Instruction Channel
     56 
     57 Lightweight management agents expose a concise instruction set parsed from the C2 queue. That set is enough to operate dozens of compromised hypervisors without interactive shells:
     58 
     59 | Instruction | Effect |
     60 | --- | --- |
     61 | `Config` | Overwrite the local JSON config that defines target directories, execution delays or throttling, enabling hot re-tasking without redeploying binaries. |
     62 | `Info` | Return hypervisor build info, IPs and adapter metadata gathered with the `uname`/`esxcli` probes. |
     63 | `Exec` | Kick off the ransomware phase: change `root` credentials, stop `vpxa`, optionally schedule a reboot delay and then pull+execute the encryptor. |
     64 | `Run` | Implement a remote shell by writing arbitrary C2-provided commands to `./shmv`, chmod +x and execute it. |
     65 | `Remove` | Issue `rm -rf <path>` for tool clean-up or destructive wiping. |
     66 | `Abort` / `Abort_f` | Stop queued encryptions or kill running worker threads if the operator wants to pause post-reboot actions. |
     67 | `Quit` | Terminate the agent and `rm -f` its binary for fast self-removal. |
     68 | `Welcome` | Abuse `esxcli system welcomemesg set -m="text"` to display ransom notices right in the console banner. |
     69 
     70 Internally these agents keep two mutex-protected JSON blobs (runtime config + status/telemetry) so that concurrent threads (e.g. beaconing + encryption workers) do not corrupt shared state. Samples are commonly padded with junk code to slow shallow static analysis but the core routines remain intact.<sup>[[1]](#references)</sup>
     71 
     72 ### Virtualization & Backup-Aware Targeting
     73 
     74 Mario-like encryptors only traverse operator-supplied directory roots and touch virtualization artefacts that matter for business continuity:
     75 
     76 | Extension | Target |
     77 | --- | --- |
     78 | `vmdk`, `vmem`, `vmsd`, `vmsn`, `vswp` | VM disks, memory snapshots and swap backing files. |
     79 | `ova`, `ovf` | Portable VM appliance bundles/metadata. |
     80 | `vib` | ESXi installation bundles that can block remediation/patching. |
     81 | `vbk`, `vbm` | Veeam VM backups + metadata to sabotage on-box restores. |
     82 
     83 Operational quirks:
     84 
     85 * Every visited directory receives `How To Restore Your Files.txt` before encryption to ensure ransom channels are advertised even on disconnected hosts.
     86 * Already processed files are skipped when their names contain `.emario`, `.marion`, `.lmario`, `.nmario`, `.mmario` or `.wmario`, preventing double encryption that would break the attackers' decryptor.
     87 * Encrypted payloads are renamed with a `*.mario`-style suffix (commonly `.emario`) so operators can verify coverage remotely in consoles or datastore listings.<sup>[[1]](#references)</sup>
     88 
     89 ### Layered Encryption Upgrades
     90 
     91 Recent Mario builds replace the original linear, single-key routine with a sparse, multi-key design optimised for multi-hundred-gigabyte VMDKs:
     92 
     93 * **Key schedule**: Generate a 32-byte primary key (stored around `var_1150`) and an independent 8-byte secondary key (`var_20`). Data is first transformed with the primary context and then re-mixed with the secondary key before disk writes.
     94 * **Per-file headers**: Metadata buffers (e.g. `var_40`) track chunk maps and flags so the attackers' private decryptor can reconstruct the sparse layout.
     95 * **Dynamic chunking**: Instead of a constant `0xA00000` loop, chunk size and offsets are recomputed based on file size, with thresholds extended up to ~8 GB to match modern VM images.
     96 * **Sparse coverage**: Only strategically chosen regions are touched, dramatically reducing runtime while still corrupting VMFS metadata, NTFS/EXT4 structures inside the guest or backup indexes.
     97 * **Instrumentation**: Upgraded builds log per-chunk byte counts and totals (encrypted/skipped/failed) to stdout, giving affiliates telemetry during live intrusions without extra tooling.<sup>[[1]](#references)</sup>
     98 
     99 ### See also
    100 
    101 Linux LPE via VMware Tools service discovery (CWE-426 / CVE-2025-41244):
    102 
    103 [Vmware Tools Service Discovery Untrusted Search Path Cve 2025 41244](/hacktricks/linux-hardening/main-system-information/kernel-lpe-cves/vmware-tools-service-discovery-untrusted-search-path-cve-2025-41244)
    104 
    105 ## References
    106 
    107 - [1] [Unit 42 – From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)