vmware-esx-vcenter.md (6616B)
1 --- 2 title: "VMware ESX / vCenter Pentesting" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/vmware-esx-vcenter....md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/vmware-esx-vcenter....md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # VMware ESX / vCenter Pentesting 14 15 ## Enumeration 16 17 ```bash 18 nmap -sV --script "http-vmware-path-vuln or vmware-version" -p <PORT> <IP> 19 msf> use auxiliary/scanner/vmware/esx_fingerprint 20 msf> use auxiliary/scanner/http/ms15_034_http_sys_memory_dump 21 ``` 22 23 ## Bruteforce 24 25 ```bash 26 msf> auxiliary/scanner/vmware/vmware_http_login 27 ``` 28 29 If you find valid credentials, you can use more metasploit scanner modules to obtain information. 30 31 ## ESXi Post-Exploitation & Ransomware Operations 32 33 ### Attack Workflow inside Virtual Estates 34 35 * **Develop**: maintain a lightweight management agent (e.g., *MrAgent*), encryptor (e.g., *Mario*), and leak infrastructure. 36 * **Infiltrate**: compromise vSphere management, enumerate hosts, steal data, and stage payloads. 37 * **Deploy**: push agents to each ESXi host, let them poll C2, and pull the encryptor when instructed. 38 * **Extort**: leak proof-of-compromise data and run ransom chats once encryption is confirmed.<sup>[[1]](#references)</sup> 39 40 ### Hypervisor Takeover Primitives 41 42 Once command execution on an ESXi console/SSH session is obtained, attackers typically run the following management commands to fingerprint and isolate the host before ransomware deployment: 43 44 ```bash 45 uname -a # hostname / build metadata for tracking 46 esxcli --formatter=csv network nic list # adapter + MAC inventory 47 esxcli --formatter=csv network ip interface ipv4 get 48 esxcli network firewall set --enabled false 49 /etc/init.d/vpxa stop # cut vCenter off from the host 50 passwd root # rotate credentials under attacker control 51 ``` 52 53 The same agent usually keeps a persistent loop that polls a hard-coded C2 URI. Any unreachable status triggers retries, meaning the beacon stays live until operators push instructions.<sup>[[1]](#references)</sup> 54 55 ### MrAgent-Style Instruction Channel 56 57 Lightweight management agents expose a concise instruction set parsed from the C2 queue. That set is enough to operate dozens of compromised hypervisors without interactive shells: 58 59 | Instruction | Effect | 60 | --- | --- | 61 | `Config` | Overwrite the local JSON config that defines target directories, execution delays or throttling, enabling hot re-tasking without redeploying binaries. | 62 | `Info` | Return hypervisor build info, IPs and adapter metadata gathered with the `uname`/`esxcli` probes. | 63 | `Exec` | Kick off the ransomware phase: change `root` credentials, stop `vpxa`, optionally schedule a reboot delay and then pull+execute the encryptor. | 64 | `Run` | Implement a remote shell by writing arbitrary C2-provided commands to `./shmv`, chmod +x and execute it. | 65 | `Remove` | Issue `rm -rf <path>` for tool clean-up or destructive wiping. | 66 | `Abort` / `Abort_f` | Stop queued encryptions or kill running worker threads if the operator wants to pause post-reboot actions. | 67 | `Quit` | Terminate the agent and `rm -f` its binary for fast self-removal. | 68 | `Welcome` | Abuse `esxcli system welcomemesg set -m="text"` to display ransom notices right in the console banner. | 69 70 Internally these agents keep two mutex-protected JSON blobs (runtime config + status/telemetry) so that concurrent threads (e.g. beaconing + encryption workers) do not corrupt shared state. Samples are commonly padded with junk code to slow shallow static analysis but the core routines remain intact.<sup>[[1]](#references)</sup> 71 72 ### Virtualization & Backup-Aware Targeting 73 74 Mario-like encryptors only traverse operator-supplied directory roots and touch virtualization artefacts that matter for business continuity: 75 76 | Extension | Target | 77 | --- | --- | 78 | `vmdk`, `vmem`, `vmsd`, `vmsn`, `vswp` | VM disks, memory snapshots and swap backing files. | 79 | `ova`, `ovf` | Portable VM appliance bundles/metadata. | 80 | `vib` | ESXi installation bundles that can block remediation/patching. | 81 | `vbk`, `vbm` | Veeam VM backups + metadata to sabotage on-box restores. | 82 83 Operational quirks: 84 85 * Every visited directory receives `How To Restore Your Files.txt` before encryption to ensure ransom channels are advertised even on disconnected hosts. 86 * Already processed files are skipped when their names contain `.emario`, `.marion`, `.lmario`, `.nmario`, `.mmario` or `.wmario`, preventing double encryption that would break the attackers' decryptor. 87 * Encrypted payloads are renamed with a `*.mario`-style suffix (commonly `.emario`) so operators can verify coverage remotely in consoles or datastore listings.<sup>[[1]](#references)</sup> 88 89 ### Layered Encryption Upgrades 90 91 Recent Mario builds replace the original linear, single-key routine with a sparse, multi-key design optimised for multi-hundred-gigabyte VMDKs: 92 93 * **Key schedule**: Generate a 32-byte primary key (stored around `var_1150`) and an independent 8-byte secondary key (`var_20`). Data is first transformed with the primary context and then re-mixed with the secondary key before disk writes. 94 * **Per-file headers**: Metadata buffers (e.g. `var_40`) track chunk maps and flags so the attackers' private decryptor can reconstruct the sparse layout. 95 * **Dynamic chunking**: Instead of a constant `0xA00000` loop, chunk size and offsets are recomputed based on file size, with thresholds extended up to ~8 GB to match modern VM images. 96 * **Sparse coverage**: Only strategically chosen regions are touched, dramatically reducing runtime while still corrupting VMFS metadata, NTFS/EXT4 structures inside the guest or backup indexes. 97 * **Instrumentation**: Upgraded builds log per-chunk byte counts and totals (encrypted/skipped/failed) to stdout, giving affiliates telemetry during live intrusions without extra tooling.<sup>[[1]](#references)</sup> 98 99 ### See also 100 101 Linux LPE via VMware Tools service discovery (CWE-426 / CVE-2025-41244): 102 103 [Vmware Tools Service Discovery Untrusted Search Path Cve 2025 41244](/hacktricks/linux-hardening/main-system-information/kernel-lpe-cves/vmware-tools-service-discovery-untrusted-search-path-cve-2025-41244) 104 105 ## References 106 107 - [1] [Unit 42 – From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)