{"id":7022,"date":"2023-09-18T10:52:54","date_gmt":"2023-09-18T10:52:54","guid":{"rendered":"https:\/\/fortgale.com\/blog\/?p=7022"},"modified":"2023-09-19T07:19:19","modified_gmt":"2023-09-19T07:19:19","slug":"7022","status":"publish","type":"post","link":"https:\/\/fortgale.com\/blog\/malware-analysis\/7022\/","title":{"rendered":"Server VMware ESXi &#8211; Ransomware Attacks in Italy"},"content":{"rendered":"<div data-colibri-id=\"4866-c1\" class=\"style-515 style-local-4866-c1 position-relative\">\n<div data-colibri-component=\"section\" data-colibri-id=\"4866-c2\" id=\"initial-content\" class=\"h-section h-section-global-spacing d-flex align-items-lg-center align-items-md-center align-items-center style-516 style-local-4866-c2 position-relative\">\n<div class=\"h-section-grid-container h-section-boxed-container\">\n<div data-colibri-id=\"4866-c3\" class=\"h-row-container gutters-row-lg-2 gutters-row-md-2 gutters-row-0 gutters-row-v-lg-2 gutters-row-v-md-2 gutters-row-v-2 style-517 style-local-4866-c3 position-relative\">\n<div class=\"h-row justify-content-lg-center justify-content-md-center justify-content-center align-items-lg-stretch align-items-md-stretch align-items-stretch gutters-col-lg-2 gutters-col-md-2 gutters-col-0 gutters-col-v-lg-2 gutters-col-v-md-2 gutters-col-v-2\">\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-518-outer style-local-4866-c4-outer\">\n<div data-colibri-id=\"4866-c4\" class=\"d-flex h-flex-basis h-column__inner h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-518 style-local-4866-c4 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100 align-self-lg-start align-self-md-start align-self-start\">\n<div data-colibri-id=\"4866-c5\" class=\"style-519 style-local-4866-c5 position-relative h-element\">\n<div>\n\n\n<p>VMware ESXi&nbsp;\n                      <a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=ransomware&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7027628557006692352\">#Ransomware<\/a>: What is going on? What does the following code means?<\/p>\n\n\n\n<p>D6C324719AD0AA50A54E4F8DED8E8220D8698DD67B218B5429466C40E7F72657C015D86C7E4A<\/p>\n\n\n\n<p>In the last few hours, several sources have reported massive <strong>Ransomware-type<\/strong> activity against <strong>VMware ESXi<\/strong> servers exposed on a public network.\n                      <br>The activity currently appears to be conducted by at least 2 different criminal groups.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/fortgale.com\/news\/wp-content\/uploads\/sites\/2\/2023\/02\/VMware-Ransomware-italia-1024x576.png\" alt=\"RansomNote ed ESXi (esxiArgs)\" class=\"wp-image-4870\" srcset=\"https:\/\/fortgale.com\/blog\/wp-content\/uploads\/sites\/2\/2023\/02\/VMware-Ransomware-italia-1024x576.png 1024w, https:\/\/fortgale.com\/blog\/wp-content\/uploads\/sites\/2\/2023\/02\/VMware-Ransomware-italia-300x169.png 300w, https:\/\/fortgale.com\/blog\/wp-content\/uploads\/sites\/2\/2023\/02\/VMware-Ransomware-italia-768x432.png 768w, https:\/\/fortgale.com\/blog\/wp-content\/uploads\/sites\/2\/2023\/02\/VMware-Ransomware-italia-1536x864.png 1536w, https:\/\/fortgale.com\/blog\/wp-content\/uploads\/sites\/2\/2023\/02\/VMware-Ransomware-italia.png 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" loading=\"lazy\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how\">How?<\/h2>\n\n\n\n<p>Both groups are exploiting a 2021 RCE vulnerability that allows malicious code (\ud835\udde5\ud835\uddee\ud835\uddfb\ud835\ude00\ud835\uddfc\ud835\uddfa\ud835\ude04\ud835\uddee\ud835\uddff\ud835\uddf2) to be launched remotely (CVE-\ud835\udfee\ud835\udfec\ud835\udfee\ud835\udfed-\ud835\udfee\ud835\udfed\ud835\udff5\ud835\udff3\ud835\udff0 )<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Current situation (4th of February)<\/h2>\n\n\n\n<p>There is currently massive hacking activity happening globally. Most of the compromised systems (around 500) were found to be in France.\n                      <br>The first server compromises emerge in Italy and Switzerland.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Italy and Switzerland<\/h2>\n\n\n\n<p>From an analysis activity, there would appear to be around 600 vulnerable servers present in Italy, 300 in Switzerland.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Other Information:<\/h2>\n\n\n\n<p>In the image an example of the security device placed by the criminal group inside a compromised server.<\/p>\n\n\n\n<p>The first steps to take at this juncture are: applying security patches and reducing the exposure of critical services to the public internet.<\/p>\n\n\n\n<p>To these should be added specific strategic assessments for securing critical systems such as a VMware server.<\/p>\n\n\n\n<p>Other Info:&nbsp;\n                      <a href=\"https:\/\/www.linkedin.com\/company\/fortgale\/\">Fortgale<\/a>\n                    <\/p>\n\n\n\n<p><strong>Our Services:<\/strong>\n                      <a href=\"https:\/\/fortgale.com\/xdr\" target=\"_blank\" rel=\"noreferrer noopener\">Fortgale Cyber Defence<\/a>\n                    <\/p>\n\n\n\n<p><strong>TOX_ID<\/strong><\/p>\n\n\n\n<p>D6C324719AD0AA50A54E4F8DED8E8220D8698DD67B218B5429466C40E7F72657C015D86C7E4A<\/p>\n\n\n\n<p>\n                      <a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=cybersecurity&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7027628557006692352\">#cybersecurity<\/a>\n                      <a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=vmware&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7027628557006692352\">#vmware<\/a>\n                      <a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=esxiargs&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7027628557006692352\">#ESXiArgs<\/a>\n                      <a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=italia&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7027628557006692352\">#italia<\/a>\n                      <a href=\"https:\/\/www.linkedin.com\/feed\/hashtag\/?keywords=svizzera&amp;highlightedUpdateUrns=urn%3Ali%3Aactivity%3A7027628557006692352\">#svizzera<\/a>\n                    <\/p>\n\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-colibri-component=\"section\" data-colibri-id=\"4866-c6\" id=\"blank\" class=\"h-section h-section-global-spacing d-flex align-items-lg-center align-items-md-center align-items-center style-520 style-local-4866-c6 position-relative\">\n<div class=\"h-section-grid-container h-section-boxed-container\">\n<div data-colibri-id=\"4866-c7\" class=\"h-row-container gutters-row-lg-2 gutters-row-md-2 gutters-row-0 gutters-row-v-lg-2 gutters-row-v-md-2 gutters-row-v-2 style-521 style-local-4866-c7 position-relative\">\n<div class=\"h-row justify-content-lg-center justify-content-md-center justify-content-center align-items-lg-stretch align-items-md-stretch align-items-stretch gutters-col-lg-2 gutters-col-md-2 gutters-col-0 gutters-col-v-lg-2 gutters-col-v-md-2 gutters-col-v-2\">\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-522-outer style-local-4866-c8-outer\">\n<div data-colibri-id=\"4866-c8\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-522 style-local-4866-c8 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-523-outer style-local-4866-c9-outer\">\n<div data-colibri-id=\"4866-c9\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-523 style-local-4866-c9 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-colibri-component=\"section\" data-colibri-id=\"4866-c14\" id=\"blank\" class=\"h-section h-section-global-spacing d-flex align-items-lg-center align-items-md-center align-items-center style-528 style-local-4866-c14 position-relative\">\n<div class=\"h-section-grid-container h-section-boxed-container\">\n<div data-colibri-id=\"4866-c15\" class=\"h-row-container gutters-row-lg-2 gutters-row-md-2 gutters-row-0 gutters-row-v-lg-2 gutters-row-v-md-2 gutters-row-v-2 style-529 style-local-4866-c15 position-relative\">\n<div class=\"h-row justify-content-lg-center justify-content-md-center justify-content-center align-items-lg-stretch align-items-md-stretch align-items-stretch gutters-col-lg-2 gutters-col-md-2 gutters-col-0 gutters-col-v-lg-2 gutters-col-v-md-2 gutters-col-v-2\">\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-530-outer style-local-4866-c16-outer\">\n<div data-colibri-id=\"4866-c16\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-530 style-local-4866-c16 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-531-outer style-local-4866-c17-outer\">\n<div data-colibri-id=\"4866-c17\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-531 style-local-4866-c17 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-colibri-component=\"section\" data-colibri-id=\"4866-c22\" id=\"blank\" class=\"h-section h-section-global-spacing d-flex align-items-lg-center align-items-md-center align-items-center style-645 style-local-4866-c22 position-relative\">\n<div class=\"h-section-grid-container h-section-boxed-container\">\n<div data-colibri-id=\"4866-c23\" class=\"h-row-container gutters-row-lg-2 gutters-row-md-2 gutters-row-0 gutters-row-v-lg-2 gutters-row-v-md-2 gutters-row-v-2 style-646 style-local-4866-c23 position-relative\">\n<div class=\"h-row justify-content-lg-center justify-content-md-center justify-content-center align-items-lg-stretch align-items-md-stretch align-items-stretch gutters-col-lg-2 gutters-col-md-2 gutters-col-0 gutters-col-v-lg-2 gutters-col-v-md-2 gutters-col-v-2\">\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-647-outer style-local-4866-c24-outer\">\n<div data-colibri-id=\"4866-c24\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-647 style-local-4866-c24 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-648-outer style-local-4866-c25-outer\">\n<div data-colibri-id=\"4866-c25\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-648 style-local-4866-c25 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-colibri-component=\"section\" data-colibri-id=\"4866-c30\" id=\"blank\" class=\"h-section h-section-global-spacing d-flex align-items-lg-center align-items-md-center align-items-center style-653 style-local-4866-c30 position-relative\">\n<div class=\"h-section-grid-container h-section-boxed-container\">\n<div data-colibri-id=\"4866-c31\" class=\"h-row-container gutters-row-lg-2 gutters-row-md-2 gutters-row-0 gutters-row-v-lg-2 gutters-row-v-md-2 gutters-row-v-2 style-654 style-local-4866-c31 position-relative\">\n<div class=\"h-row justify-content-lg-center justify-content-md-center justify-content-center align-items-lg-stretch align-items-md-stretch align-items-stretch gutters-col-lg-2 gutters-col-md-2 gutters-col-0 gutters-col-v-lg-2 gutters-col-v-md-2 gutters-col-v-2\">\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-655-outer style-local-4866-c32-outer\">\n<div data-colibri-id=\"4866-c32\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-655 style-local-4866-c32 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-656-outer style-local-4866-c33-outer\">\n<div data-colibri-id=\"4866-c33\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-656 style-local-4866-c33 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-colibri-component=\"section\" data-colibri-id=\"4866-c38\" id=\"blank\" class=\"h-section h-section-global-spacing d-flex align-items-lg-center align-items-md-center align-items-center style-661 style-local-4866-c38 position-relative\">\n<div class=\"h-section-grid-container h-section-boxed-container\">\n<div data-colibri-id=\"4866-c39\" class=\"h-row-container gutters-row-lg-2 gutters-row-md-2 gutters-row-0 gutters-row-v-lg-2 gutters-row-v-md-2 gutters-row-v-2 style-662 style-local-4866-c39 position-relative\">\n<div class=\"h-row justify-content-lg-center justify-content-md-center justify-content-center align-items-lg-stretch align-items-md-stretch align-items-stretch gutters-col-lg-2 gutters-col-md-2 gutters-col-0 gutters-col-v-lg-2 gutters-col-v-md-2 gutters-col-v-2\">\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-663-outer style-local-4866-c40-outer\">\n<div data-colibri-id=\"4866-c40\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-663 style-local-4866-c40 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-664-outer style-local-4866-c41-outer\">\n<div data-colibri-id=\"4866-c41\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-664 style-local-4866-c41 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div data-colibri-component=\"section\" data-colibri-id=\"4866-c46\" id=\"blank\" class=\"h-section h-section-global-spacing d-flex align-items-lg-center align-items-md-center align-items-center style-669 style-local-4866-c46 position-relative\">\n<div class=\"h-section-grid-container h-section-boxed-container\">\n<div data-colibri-id=\"4866-c47\" class=\"h-row-container gutters-row-lg-2 gutters-row-md-2 gutters-row-0 gutters-row-v-lg-2 gutters-row-v-md-2 gutters-row-v-2 style-670 style-local-4866-c47 position-relative\">\n<div class=\"h-row justify-content-lg-center justify-content-md-center justify-content-center align-items-lg-stretch align-items-md-stretch align-items-stretch gutters-col-lg-2 gutters-col-md-2 gutters-col-0 gutters-col-v-lg-2 gutters-col-v-md-2 gutters-col-v-2\">\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-671-outer style-local-4866-c48-outer\">\n<div data-colibri-id=\"4866-c48\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-671 style-local-4866-c48 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"h-column h-column-container d-flex h-col-lg-auto h-col-md-auto h-col-auto style-672-outer style-local-4866-c49-outer\">\n<div data-colibri-id=\"4866-c49\" class=\"d-flex h-flex-basis h-column__inner h-ui-empty-state-container h-px-lg-2 h-px-md-2 h-px-2 v-inner-lg-2 v-inner-md-2 v-inner-2 style-672 style-local-4866-c49 position-relative\">\n<div class=\"w-100 h-y-container h-column__content h-column__v-align flex-basis-100\"><\/div>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>VMware ESXi&nbsp; #Ransomware: What is going on? What does the following code means? D6C324719AD0AA50A54E4F8DED8E8220D8698DD67B218B5429466C40E7F72657C015D86C7E4A In the last few hours, several sources have reported massive Ransomware-type activity against VMware ESXi servers exposed on a public network. The activity currently appears to be conducted by at least 2 different criminal groups. How? Both groups are exploiting a [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":4870,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2483],"tags":[283,2501],"class_list":["post-7022","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-analysis","tag-ransomware","tag-wmare-esxi"],"_links":{"self":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/7022","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/comments?post=7022"}],"version-history":[{"count":11,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/7022\/revisions"}],"predecessor-version":[{"id":7039,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/7022\/revisions\/7039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/media\/4870"}],"wp:attachment":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/media?parent=7022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/categories?post=7022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/tags?post=7022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}