ESXi Payload Executed Against Datastore
Description
Detects a program launched from the ESXi shell against /vmfs/volumes. The datastore holds the virtual disks of
every guest. A process pointed at that path can read or encrypt those disks and take the hosted virtual machines
offline.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:("/vmfs/volumes" and ("/tmp/" or python))
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- A support script stored under `/tmp` or a Python inventory check can be pointed at a datastore during maintenance. Confirm the file name, the account, and whether virtual machines were shut down in the same session.
Analyst notes
Investigating ESXi Payload Executed Against Datastore
This is the launch command. A path under /tmp, or python, is invoked with /vmfs/volumes as an argument. Ragnar Locker uses /tmp/ /vmfs/volumes//. Pysa uses Python and passes the datastore path.
Possible investigation steps
- Read message for the executable path and the datastore argument.
- Check the same session for chmod +x, VM process kills, snapshot removal, and find commands for vmdk files.
- On the host, identify the file that was executed and whether it is still under /tmp or on a datastore.
False positive analysis
Approved maintenance can run a known script from /tmp against a datastore. An unknown filename, especially after a chmod in the same session, is the ransomware launch pattern.
Response and remediation
- If the program was not approved, isolate the host. Leave powered-on VMs running so their disks stay locked.
- Remove the file under /tmp and preserve shell.log.
- Restore any datastore that was modified from an off-host backup.