http://torzcd47rw4qh36g4yqxvv2tmifgmu6jjalkyqz4e4lzzwtfdfc7qaqd.onion/vmware-user-worried-about-esxi-ransomware-check-your-patches-now-mobile-hacker-for-hire/index.html
The crooks use the find command on each volume in your /vmfs/volumes/ directory to locate files from this list of extensions: .vmdk , .vmx , .vmxf , .vmsd , .vmsn , .vswp , .vmss , .nvram and .vmem . Call a general-purpose file scrambling tool for each file found. A program called encrypt , uploaded by the crooks, is used to scramble each file individually in a separate process.