File scene.jpg

Size 293.4KB
Type JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1280x720, components 3
MD5 016e4a0183b7e470be6788bc39ad3df1
SHA1 7a790ce8c886961c87a6d09dd02a8313fb0cdefa
SHA256 769c746d552691439fb499124c6a48acdaa3bb528c899476856d7bf8e6ba3f18
SHA512
1d431658e7108db73bdf5d1f0bac5b2559a38c08efea636026484c13ba7b8ad733406c38baed1210f19eb038ba7493b3bd1252708656297c98949d2242c8df3d
CRC32 C5149731
ssdeep None
Yara None matched

Score

This file appears fairly benign with a score of 0.6 out of 10.

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Feb. 7, 2026, 2:16 p.m. Feb. 7, 2026, 2:17 p.m. 81 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2026-02-07 13:16:21,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi
2026-02-07 13:16:21,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\SdxtdRQxcBTgUchDkYFR
2026-02-07 13:16:21,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\tsHYMMPMuIbZdfUMHowEzuVZiDaPawW
2026-02-07 13:16:21,342 [analyzer] DEBUG: Started auxiliary module Curtain
2026-02-07 13:16:21,358 [analyzer] DEBUG: Started auxiliary module DbgView
2026-02-07 13:16:21,765 [analyzer] DEBUG: Started auxiliary module Disguise
2026-02-07 13:16:21,967 [analyzer] DEBUG: Loaded monitor into process with pid 512
2026-02-07 13:16:21,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2026-02-07 13:16:21,967 [analyzer] DEBUG: Started auxiliary module Human
2026-02-07 13:16:21,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2026-02-07 13:16:21,967 [analyzer] DEBUG: Started auxiliary module Reboot
2026-02-07 13:16:22,092 [analyzer] DEBUG: Started auxiliary module RecentFiles
2026-02-07 13:16:22,092 [analyzer] DEBUG: Started auxiliary module Screenshots
2026-02-07 13:16:22,092 [analyzer] DEBUG: Started auxiliary module Sysmon
2026-02-07 13:16:22,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2026-02-07 13:16:22,171 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\rundll32.exe' with arguments ['C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll', 'ImageView_Fullscreen', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\scene.jpg'] and pid 2936
2026-02-07 13:16:22,405 [analyzer] DEBUG: Loaded monitor into process with pid 2936
2026-02-07 13:17:36,638 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2026-02-07 13:17:36,904 [analyzer] INFO: Terminating remaining processes before shutdown.
2026-02-07 13:17:36,904 [lib.api.process] INFO: Successfully terminated process with pid 2936.
2026-02-07 13:17:36,904 [analyzer] INFO: Analysis completed.

Cuckoo Log

2026-02-07 14:16:27,045 [cuckoo.core.scheduler] INFO: Task #7451917: acquired machine win7x6410 (label=win7x6410)
2026-02-07 14:16:27,167 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #7451917
2026-02-07 14:16:27,512 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 410587 (interface=vboxnet0, host=192.168.168.210)
2026-02-07 14:16:27,534 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410
2026-02-07 14:16:28,093 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak
2026-02-07 14:16:58,617 [cuckoo.core.guest] INFO: Starting analysis #7451917 on guest (id=win7x6410, ip=192.168.168.210)
2026-02-07 14:16:59,623 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet
2026-02-07 14:17:04,647 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210)
2026-02-07 14:17:04,788 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546)
2026-02-07 14:17:06,408 [cuckoo.core.resultserver] DEBUG: Task #7451917: live log analysis.log initialized.
2026-02-07 14:17:07,321 [cuckoo.core.resultserver] DEBUG: Task #7451917 is sending a BSON stream
2026-02-07 14:17:07,665 [cuckoo.core.resultserver] DEBUG: Task #7451917 is sending a BSON stream
2026-02-07 14:17:08,644 [cuckoo.core.resultserver] DEBUG: Task #7451917: File upload for 'shots/0001.jpg'
2026-02-07 14:17:08,658 [cuckoo.core.resultserver] DEBUG: Task #7451917 uploaded file length: 133432
2026-02-07 14:17:21,016 [cuckoo.core.guest] DEBUG: win7x6410: analysis #7451917 still processing
2026-02-07 14:17:36,108 [cuckoo.core.guest] DEBUG: win7x6410: analysis #7451917 still processing
2026-02-07 14:17:36,818 [cuckoo.core.resultserver] DEBUG: Task #7451917: File upload for 'curtain/1770466656.81.curtain.log'
2026-02-07 14:17:36,822 [cuckoo.core.resultserver] DEBUG: Task #7451917 uploaded file length: 36
2026-02-07 14:17:36,897 [cuckoo.core.resultserver] DEBUG: Task #7451917: File upload for 'sysmon/1770466656.89.sysmon.xml'
2026-02-07 14:17:36,910 [cuckoo.core.resultserver] DEBUG: Task #7451917 uploaded file length: 463318
2026-02-07 14:17:37,500 [cuckoo.core.resultserver] DEBUG: Task #7451917 had connection reset for <Context for LOG>
2026-02-07 14:17:39,121 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully
2026-02-07 14:17:39,133 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-02-07 14:17:39,155 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-02-07 14:17:40,172 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/7451917/memory.dmp
2026-02-07 14:17:40,173 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410
2026-02-07 14:17:47,861 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #7451917
2026-02-07 14:17:48,239 [cuckoo.core.scheduler] DEBUG: Released database task #7451917
2026-02-07 14:17:48,255 [cuckoo.core.scheduler] INFO: Task #7451917: analysis procedure completed

Signatures

Allocates read-write-execute memory (usually to unpack itself) (1 event)
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000021f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0
Checks if process is being debugged by a debugger (1 event)
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate) (1 event)
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 event)
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.