http://torzcd47rw4qh36g4yqxvv2tmifgmu6jjalkyqz4e4lzzwtfdfc7qaqd.onion/vmware-user-worried-about-esxi-ransomware-check-your-patches-now-mobile-hacker-for-hire/index.html
Note that the malware contains its own implementation of the Sosemanuk cipher algorithm, though it relies on OpenSSL for the random numbers it uses, and for the RSA public-key processing it does: Generate PUBKEY , an RSA public key, by reading in PEMFILE . Generate RNDKEY , a random, 32-byte symmetric encryption key. Go to the beginning of FILENAME Read in M megabytes from FILENAME . Scramble that data using the Sosemanuk stream cipher with RNDKEY .