File name:

LockBit_LINUX_AMD64.elf

Full analysis: https://app.any.run/tasks/56681ca4-6424-41e2-8540-1026eac0f31e
Verdict: Malicious activity
Threats:

LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.

Analysis date: October 30, 2025, 23:28:51
OS: Ubuntu 22.04.2
Tags:
auto
lockbit
ransomware
lockbit5
Indicators:
MIME: application/x-executable
File info: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, no section header
MD5:

CA93D47BCC55E2E1BD4A679AFC8E2E25

SHA1:

41E1E094C19FFFDE494C24EF4CAB0D7577D5A025

SHA256:

4DC06ECEE904B9165FA699B026045C1B6408CC7061DF3D2A7BC2B7B4F0879F4D

SSDEEP:

6144:3/OeE8Hhv7EqKsu2kyzFnNQaIAGbo+rMlIIuq:3/OeE8Hhv7Rbu2kyHQYGbo+rMlpuq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LOCKBIT5.0 has been detected

      • LockBit_LINUX_AMD64.elf (PID: 1901)
  • SUSPICIOUS

    • Modifies file or directory owner

      • sudo (PID: 1897)
    • Writes to Systemd service files (likely for persistence achievement)

      • sudo (PID: 1900)
    • SSH config modification

      • LockBit_LINUX_AMD64.elf (PID: 1901)
    • Modifies Cron jobs

      • sudo (PID: 1900)
    • Reads passwd file

      • whoopsie (PID: 1932)
  • INFO

    • Creates file in the temporary folder

      • LockBit_LINUX_AMD64.elf (PID: 1901)
    • Checks timezone

      • whoopsie (PID: 1932)
      • python3.10 (PID: 1937)
      • python3.10 (PID: 1935)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.o | ELF Executable and Linkable format (generic) (49.8)

EXIF

EXE

CPUArchitecture: 64 bit
CPUByteOrder: Little endian
ObjectFileType: Executable file
CPUType: AMD x86-64
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
19
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1896/bin/sh -c "sudo chown user /home/user/Desktop/LockBit_LINUX_AMD64\.elf && chmod +x /home/user/Desktop/LockBit_LINUX_AMD64\.elf && DISPLAY=:0 sudo -i /home/user/Desktop/LockBit_LINUX_AMD64\.elf "/usr/bin/dashUfXVfoM3bYObT5IV
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
1897sudo chown user /home/user/Desktop/LockBit_LINUX_AMD64.elf/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0
/usr/lib/x86_64-linux-gnu/libselinux.so.1
/usr/libexec/sudo/libsudo_util.so.0.0.0
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
/usr/lib/x86_64-linux-gnu/libnss_systemd.so.2
/usr/libexec/sudo/sudoers.so
/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1
/usr/lib/x86_64-linux-gnu/libz.so.1.2.11
1898chown user /home/user/Desktop/LockBit_LINUX_AMD64.elf/usr/bin/chownsudo
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
1899chmod +x /home/user/Desktop/LockBit_LINUX_AMD64.elf/usr/bin/chmoddash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
1900sudo -i /home/user/Desktop/LockBit_LINUX_AMD64.elf/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0
/usr/lib/x86_64-linux-gnu/libselinux.so.1
/usr/libexec/sudo/libsudo_util.so.0.0.0
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
/usr/lib/x86_64-linux-gnu/libnss_systemd.so.2
/usr/libexec/sudo/sudoers.so
/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1
/usr/lib/x86_64-linux-gnu/libz.so.1.2.11
1901/home/user/Desktop/LockBit_LINUX_AMD64.elf/home/user/Desktop/LockBit_LINUX_AMD64.elf
sudo
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libtinfo.so.6.3
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libpthread.so.0
/usr/lib/x86_64-linux-gnu/libgcc_s.so.1
1902/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkLockBit_LINUX_AMD64.elf
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
1903-bash --login -c \/home\/user\/Desktop\/LockBit_LINUX_AMD64\.elf/usr/bin/bashLockBit_LINUX_AMD64.elf
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
1904sh -c "cat /usr/etc/debuginfod/*\.urls 2>/dev/null"/usr/bin/dashbash
User:
root
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
1905tr \n " "/usr/bin/trbash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
Executable files
0
Suspicious files
81
Text files
151
Unknown types
0

Dropped files

PID
Process
Filename
Type
1901LockBit_LINUX_AMD64.elf/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/media/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/user/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/user/.mozilla/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/user/.mozilla/extensions/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/user/.mozilla/firefox/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/user/.mozilla/firefox/Profile Groups/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/user/.mozilla/firefox/Pending Pings/ReadMeForDecrypt.txttext
MD5:
SHA256:
1901LockBit_LINUX_AMD64.elf/home/user/.mozilla/firefox/2rayb35q.default/ReadMeForDecrypt.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
204
185.125.190.48:80
http://connectivity-check.ubuntu.com/
GB
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.125.190.48:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
whitelisted
465
avahi-daemon
224.0.0.251:5353
whitelisted
185.125.190.98:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
whitelisted
185.125.190.58:123
ntp.ubuntu.com
whitelisted

DNS requests

Domain
IP
Reputation
connectivity-check.ubuntu.com
  • 2620:2d:4002:1::197
  • 2620:2d:4000:1::2b
  • 2620:2d:4002:1::196
  • 2620:2d:4000:1::98
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::23
  • 2620:2d:4002:1::198
  • 2001:67c:1562::24
  • 2620:2d:4000:1::22
  • 2620:2d:4000:1::97
  • 2001:67c:1562::23
  • 2620:2d:4000:1::96
  • 185.125.190.48
  • 185.125.190.18
  • 91.189.91.49
  • 185.125.190.98
  • 91.189.91.48
  • 91.189.91.96
  • 185.125.190.97
  • 185.125.190.96
  • 185.125.190.49
  • 185.125.190.17
  • 91.189.91.98
  • 91.189.91.97
whitelisted
google.com
  • 216.58.206.46
  • 2a00:1450:4001:81d::200e
whitelisted
ntp.ubuntu.com
  • 185.125.190.58
  • 185.125.190.56
  • 91.189.91.157
  • 185.125.190.57
  • 2620:2d:4000:1::41
  • 2620:2d:4000:1::3f
  • 2620:2d:4000:1::40
whitelisted
9.100.168.192.in-addr.arpa
whitelisted

Threats

No threats detected
No debug info