Using Hybrid Analysis for malicious file analysis
You can also use an online tool such as Hybrid Analysis (https://www.hybrid-analysis.com/) to analyze suspicious files of all types. If you suspect that a link or URL may be suspicious within an email, you can also paste the link into this site for analysis.
As an example, I’ll use the very same testpdf.pdf
file that I analyzed using pdf-parse
and PDFiD
in the previous section. I’ll first visit the https://www.hybrid-analysis.com website and drag the suspect file into the upload area and click on Analyze, as seen in the following screenshot.
Figure 11.19 – hybrid-analysis.com website
After submitting the PDF file, the results show the file to be possibly malicious, as seen in the following screenshot:
Figure 11.20 – hybrid-analysis.com file analysis and results
The details on the file’s unusual characteristics and suspicious indicators...