RANSOMWARE - BEAST Cross-Platform ESXi Encryption Staging
Detects network activity related to the BEAST ransomware targeting VMware ESXi systems. The rule identifies attempts to stage encryption operations via SSH, including detecting references to known filenames ('encryptor.elf', 'beast_esxi') and the use of the 'vim-cmd' utility to power off virtual machines as part of the preparation for file encryption.
Suricata

