Evidence Analysis

Evidence thumbnail
Critical VISION: Label detected VISION: Label detected VISION: Label detected VISION: Label detected VISION: Label detected STEGO: JPEG embedded data STEGO: Hidden text found in file bytes
Evidence_Dump\13guns-zkcq-mediumSquareAt3X.jpg
Vision API Objects
Air gun, Airsoft gun, Firearm, Gun, Gun barrel
Entropy Analysis
7.58
Hidden Message Decoded
.IEC 61966-2.1 Default RGB colour space - sRGB
Detailed Findings (7)
  • High - VISION: Firearm (0.99)
  • High - VISION: Gun (0.99)
  • High - VISION: Air gun (0.86)
  • High - VISION: Gun barrel (0.85)
  • High - VISION: Airsoft gun (0.74)
  • Critical - STEGO: Mode: rgb/bit1 | JPEG signature at offset 66088. Bytes: ffd8ffe38e1d7a807db4aa3b63b108708729700e1da38cc4ec49fdffffd80fc06dc72392224ea2fe954b8f5571db15b15b51e0991a0028d15724fdaa9a8ab6db | Saved: Evidence_Dump\_stego_extract\13guns-zkcq-mediumSquareAt3X_rgb_bit1.jpg
  • Critical - STEGO: .IEC 61966-2.1 Default RGB colour space - sRGB
Evidence thumbnail
Critical QR: QR code found STEGO: BMP embedded data
Evidence_Dump\3-2BTechnology-2BKids.jpg
OCR Text Detected
OR Codes for Kids
QR Code Data
http://www.sciencekiddo.com/2015/01/qr-codes-for-kids-introduction-to.html
Vision API Objects
2D barcode
Entropy Analysis
3.70
Critical Finding
Embedded bmp embedded data detected using rgb/bit0 extraction
Detailed Findings (2)
  • High - QR: URL: http://www.sciencekiddo.com/2015/01/qr-codes-for-kids-introduction-to.html
  • Critical - STEGO: Mode: rgb/bit0 | BMP signature at offset 118687. Bytes: 424db6d27ffc093126200003803fffffff3f90128aebfbd800009eec749000001c05096dc7e30000001f81ff0000006634ac8824a4000000000e00920480c47c
Evidence thumbnail
Critical STEGO: BMP embedded data
Evidence_Dump\ER22_3302_HeaderArt_1600x900.jpg
OCR Text Detected
SCAN ME SCAN ME
Vision API Objects
2D barcode
Entropy Analysis
2.79
Critical Finding
Embedded bmp embedded data detected using rgb/bit0 extraction
Detailed Findings (1)
  • Critical - STEGO: Mode: rgb/bit0 | BMP signature at offset 84113. Bytes: 424d230eacc0edaa5018d166d0c76c0803f000d801b324ef3df123fc6d2926000000000000000000000000000000000000000000000000000000000000000000
Evidence thumbnail
Critical QR: QR code found STEGO: Hidden text found in file bytes
Evidence_Dump\Screen-Shot-2022-10-31-at-1.45.46-PM.png
OCR Text Detected
Enter or paste website URL Create QR Code Generate QR Code Powered by Adobe Express Style cH eo eee Color @eeee File Type PNG v
QR Code Data
https://express.adobe.com
Vision API Objects
2D barcode
Entropy Analysis
1.91
Hidden Message Decoded
812
Detailed Findings (2)
  • High - QR: URL: https://express.adobe.com
  • Critical - STEGO: 812
Evidence thumbnail
Low
Evidence_Dump\Visa-Card_Rewards_Final.png
OCR Text Detected
texas dos credit union |) 4019 1254 5678 9010 tHru 00/00 CARDHOLDER NAME VISA
Entropy Analysis
1.80
No Preview
Low
Evidence_Dump\_stego_extract\13guns-zkcq-mediumSquareAt3X_rgb_bit1.jpg
No Preview
Low
Evidence_Dump\_stego_extract\password-generator-2.0_r_bit2.jpg
Evidence thumbnail
Critical VISION: Label detected VISION: Label detected STEGO: Suspected steganography / high noise STEGO: BMP embedded data STEGO: Hidden text found in file bytes
Evidence_Dump\best-credit-card-cnnu.jpg
OCR Text Detected
y W un (ow Sy AMERICAN EXPR
Vision API Objects
Credit card, Payment card
Entropy Analysis
7.27
Hidden Message Decoded
((((((((((((((((((((((((((((((((((((((((((((((((((
Detailed Findings (5)
  • Medium - VISION: Payment card (0.75)
  • High - VISION: Credit card (0.53)
  • Medium - STEGO: Entropy: 7.27 | LSB chi2: 14.66 | HF energy: 453.3
  • Critical - STEGO: Mode: rgb/bit2 | BMP signature at offset 160799. Bytes: 424db49b6db6d24db6d789b0089b3276dd9276dffda4db6da6edfd26db003fe00ff8000038000fff000022fd80bf09b692013fedbff6fffedb2dedbffc09b425
  • Critical - STEGO: ((((((((((((((((((((((((((((((((((((((((((((((((((
Evidence thumbnail
Critical STEGO: BMP embedded data
Evidence_Dump\canvas.png
Vision API Objects
Clothing, Person
Entropy Analysis
5.85
Hidden Message Decoded
My bank account password is "NoobMan@420"
Detailed Findings (1)
  • Critical - STEGO: Mode: rgb/bit1 | BMP signature at offset 129. Bytes: 424d8e2766eb34aae32ae3515adb9296256b7548a38e35ff1c456a495aaa552b6d56da95b524aa56aaad91c8e472491b71b8e48db8e36db92491b92371c6e472
Evidence thumbnail
Critical STEGO: LSB text decoded
Evidence_Dump\canvas1.png
Entropy Analysis
1.79
Hidden Message Decoded
My tinder account password is "Beat the heat, grill the meat, keep it neat"
Detailed Findings (1)
  • Critical - STEGO: Mode: rgb/bit0 | My tinder account password is "Beat the heat, grill the meat, keep it neat"
Evidence thumbnail
Critical VISION: Label detected VISION: Label detected VISION: Label detected STEGO: BMP embedded data
Evidence_Dump\fsb-credit-card_contactless.png
OCR Text Detected
5412 7534 5678 9010 9412 VALID (0/00 LEE M. CARDHOLDER
Vision API Objects
Credit card, Debit card, Payment card
Entropy Analysis
5.87
Critical Finding
Embedded bmp embedded data detected using rgb/bit0 extraction
Detailed Findings (4)
  • Medium - VISION: Payment card (0.83)
  • Medium - VISION: Debit card (0.60)
  • High - VISION: Credit card (0.55)
  • Critical - STEGO: Mode: rgb/bit0 | BMP signature at offset 89677. Bytes: 424d20825848e49a6d0a8b26ca300221b4ffebecff7320802daf2ebfdad921a0009041248452df0ca8c0082bda6bfcb2fbffbefeffeff7820d0cc86692780014
Evidence thumbnail
Critical VISION: Label detected VISION: Label detected VISION: Label detected VISION: Label detected VISION: Label detected STEGO: Suspected steganography / high noise STEGO: BMP embedded data STEGO: Hidden text found in file bytes
Evidence_Dump\images.jpg
Vision API Objects
Air gun, Airsoft gun, Firearm, Gun, Gun barrel
Entropy Analysis
7.46
Hidden Message Decoded
-% &--------------------------------------------------
Detailed Findings (8)
  • High - VISION: Firearm (0.98)
  • High - VISION: Gun (0.98)
  • High - VISION: Air gun (0.86)
  • High - VISION: Gun barrel (0.79)
  • High - VISION: Airsoft gun (0.53)
  • Medium - STEGO: Entropy: 7.46 | LSB chi2: 2.87 | HF energy: 2987.4
  • Critical - STEGO: Mode: rgb/bit1 | BMP signature at offset 13903. Bytes: 424d6de07cd9a0bc7ad9d6e4945d51d4621124dd30e082370215a94cc068a12d5a3545d2df079d8ed89ff52b9426db7b63645c9159eb7dcfde7dc9a890066c8c
  • Critical - STEGO: -% &--------------------------------------------------
Evidence thumbnail
Critical OCR: OCR match VISION: Label detected STEGO: JPEG embedded data
Evidence_Dump\password-generator-2.0.png
OCR Text Detected
Password Generator Password Generator Online Help Character Set Password Length Capital letters (A..Z) _ (small letters (a..z) 9 [1] Numbers (0..9) Your Password: OQXHWSZKX Trial version: 10 day
Vision API Objects
Computer program
Entropy Analysis
3.33
Hidden Message Decoded
V%bV'bv'bv'bv'bv'bv'br'"r'"r'2s'
Detailed Findings (3)
  • Critical - OCR: Keyword(s): password
  • Medium - VISION: Computer program (0.52)
  • Critical - STEGO: Mode: r/bit2 | JPEG signature at offset 10321. Bytes: ffd8ffe9fffe7fe7ffeffffb5c6dfffffffe6a6b5ffc97847eefff3ffedbad7db7ffd75bdbffa70f966f3fe17ffffffffffffffffffffffffffffffbfeffc3cf | Saved: Evidence_Dump\_stego_extract\password-generator-2.0_r_bit2.jpg
Evidence thumbnail
Critical STEGO: JPEG embedded data STEGO: Hidden text found in file bytes
Evidence_Dump\set-of-qr-codecodes-template-with-inscriptionisolated-on-white-backgroundvector-illustration-2BWMNDK.jpg
OCR Text Detected
Happy New Year! OF mi Happy Birthday! Open 24 Hours
Vision API Objects
2D barcode
Entropy Analysis
2.69
Hidden Message Decoded
;("(;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
Detailed Findings (2)
  • Critical - STEGO: Mode: rgb/bit2 | JPEG signature at offset 147283. Bytes: ffd8fffffffffffffff1c7ffffc7ffffffffffffffffffff8e07bffffdf3f9fdffffffffffffffffffffffffe3f1f81faff8feffffffffffffffff5ffffcffff
  • Critical - STEGO: ;("(;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
Evidence thumbnail
Critical OCR: OCR match STEGO: BMP embedded data STEGO: Hidden text found in file bytes
Evidence_Dump\v4-460px-Create-a-Secure-Password-Step-3-Version-2.jpg
OCR Text Detected
PASSWORD: €} 1292014 ©) wio01292014etv wiki
Entropy Analysis
4.84
Hidden Message Decoded
UUUUUUUUUUUUUUUUUUUUUBt
Detailed Findings (3)
  • Critical - OCR: Keyword(s): password
  • Critical - STEGO: Mode: g/bit0 | BMP signature at offset 1681. Bytes: 424dc402b46ec75a54776be34635601d5f110423c530c187e31a1a081ea3b02c3f4916962d3a2a590f2382bc54bd5270ef9e84c9767bc0cc694e1819969aad8c
  • Critical - STEGO: %&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz