4B

VMDK (VMware disk) file signature

Magic number at the start of the file · KDMV

4B 44 4D 56

A monolithic sparse VMware disk starts with the magic KDMV. Some VMDKs are instead a short text descriptor beginning '# Disk DescriptorFile' that points to separate data extents.

Hex signature
4B 44 4D 56
Offset
0 (start of file)
ASCII
KDMV
Length
4 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 4B 44 4D 56 (the text KDMV), it is a VMDK (VMware disk) file.

Formats that use the 4B 44 4D 56 signature

These file types in our database carry this signature:

How to check a file's signature

You can read the first bytes of any file yourself. The magic bytes are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.vmdk
  • hexdump -C -n 16 example.vmdk
  • file example.vmdk

Windows (PowerShell)

  • Format-Hex -Path example.vmdk -Count 16

Python

  • open("example.vmdk","rb").read(4).hex()

In your browser

Frequently asked questions

What is the VMDK (VMware disk) file signature?

VMDK (VMware disk) files start with the hex bytes 4B 44 4D 56 (KDMV in ASCII). This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.vmdk on Linux or macOS, or Format-Hex -Path example.vmdk -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the VMDK (VMware disk) signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine VMDK (VMware disk) file has these exact bytes; a file with the wrong bytes is not really VMDK (VMware disk), whatever its name says.

Related signatures

Sources