How to Detect and Analyze PDF Malware: A Beginner's Step-by-Step Method

Learn how to detect and analyze PDF malware using simple, beginner-friendly steps. PDF malware is a growing cyber threat where attackers embed malicious JavaScript, links, or files inside PDF documents. This guide explains how to set up a safe malware analysis environment, identify suspicious PDF characteristics, extract and analyze hidden JavaScript, review embedded files and links, perform static and dynamic analysis, and use free tools like pdfid.py, pdf-parser.py, VirusTotal, and CyberChef. The blog is designed for IT professionals, students, and cybersecurity beginners looking to develop hands-on malware analysis skills without needing advanced experience.

Jul 18, 2025 - 10:34
Updated: 7 days ago
107.8k
How to Detect and Analyze PDF Malware: A Beginner's Step-by-Step Method

Quick answer: To analyse a suspicious PDF safely, work in an isolated virtual machine, never open it in a normal reader, hash the file, scan it with pdfid and look for risky keywords such as /JavaScript, /OpenAction, /Launch and /EmbeddedFile. Then inspect the objects with pdf-parser, extract links, and check indicators against threat intelligence.

Key takeaways

  • Never open a suspect PDF on your main machine. Use an isolated VM with no shared folders and a snapshot.
  • Triage first: hash, file type, then pdfid to count risky keywords.
  • Risky markers include /JavaScript, /JS, /OpenAction, /AA, /Launch, /EmbeddedFile and /URI.
  • Many malicious PDFs are phishing carriers with links or QR codes, not exploits. Check where links lead.
  • Record hashes, URLs and findings, and report them; do not just delete the file.

Why are PDFs used to deliver malware?

PDF is trusted, widely shared and supports features beyond text: embedded JavaScript, forms, file attachments and links. Attackers use it in two main ways. The first is exploiting a bug in a PDF reader, which is less common today because readers are patched and sandboxed. The second, and more frequent, is using the PDF as a lure: it contains a link or a QR code that sends the victim to a phishing page or a malware download. A good analyst checks for both.

How do you set up a safe analysis environment?

  1. Use a virtual machine, for example a Linux VM, with a snapshot you can restore.
  2. Disable shared folders, clipboard sharing and drag and drop.
  3. Turn off the network, or place the VM on an isolated host-only network, unless you deliberately need to test a link in a controlled way.
  4. Install the analysis tools beforehand, because you will not have internet access during analysis.
  5. Do not open the PDF in a graphical reader. Analyse it as data using command-line tools.

What is the step-by-step workflow?

  1. Record the basics. Compute a hash so you can identify the file and look it up later.
    sha256sum suspicious.pdf
    file suspicious.pdf
    exiftool suspicious.pdf
    The file command confirms it really is a PDF, and exiftool shows metadata such as creator and dates.
  2. Look up the hash. From your normal machine, search the hash on VirusTotal. Do not upload confidential documents, because uploaded files can be seen by others.
  3. Triage with pdfid. Didier Stevens' pdfid.py counts important keywords.
    python3 pdfid.py suspicious.pdf
    Read the counts for /JS, /JavaScript, /OpenAction, /AA, /Launch, /EmbeddedFile, /RichMedia and /URI. A normal one-page document usually has none of the first ones.
  4. Inspect objects with pdf-parser. Search for the suspicious keyword and read the object around it.
    python3 pdf-parser.py --search javascript suspicious.pdf
    python3 pdf-parser.py --object 12 --filter --raw suspicious.pdf
    The --filter option decodes compressed streams so you can read the content.
  5. Extract URLs and attachments. List /URI entries and any embedded files. Defang URLs before putting them in notes, for example hxxps://example[.]com.
  6. Read any script as text. Obfuscated JavaScript often hides a download address or shellcode. Describe what it does; do not run it.
  7. Decide and document. Write the hashes, keywords found, URLs and your conclusion. Report to your security team or mail provider.

What do the keywords mean?

KeywordMeaningWhy it matters
/JavaScript, /JSEmbedded scriptCan run code or hide exploit logic
/OpenAction, /AAAction run when the file opens or an event occursAutomatic execution trigger
/LaunchStart an external programRare in benign files
/EmbeddedFileAttached fileMay hide another malicious file
/URILinkCommon in phishing lures
/Encrypt, odd filtersEncryption or stacked encodingsUsed to evade scanners

One keyword does not prove malice. Forms and legitimate business PDFs use JavaScript too. Look at combinations and at what the script does.

Worked scenario

This is an illustrative case, not a real incident. An employee gets an "invoice.pdf". The hash is unknown to VirusTotal. pdfid reports no JavaScript, no OpenAction, but one /URI and a large image. Opening the file as an image shows a QR code with the text "scan to view payment". Decoding the QR code in the VM reveals a link to a login-style page on an unrelated domain. Verdict: a phishing lure with no exploit. Actions: block the domain, remove the message from other mailboxes, and warn users about QR phishing.

Common mistakes

  • Double-clicking the file "just to see".
  • Uploading a confidential PDF to a public scanning site.
  • Assuming no JavaScript means safe, forgetting links and QR codes.
  • Running recovered scripts to see what happens.
  • Forgetting that analysing real samples needs authorisation in a workplace.

Next steps

For more on scanning files and URLs, read VirusTotal explained and QR code phishing in PDFs. To learn analysis methods properly, see our CHFI forensics course or the SOC analyst course.

Related reading

Frequently Asked Questions

Open it only in an isolated virtual machine as data, not in a reader. Hash it, scan with pdfid for keywords such as /JavaScript and /OpenAction, inspect objects with pdf-parser and check any links against threat intelligence.

Yes, but it is more often a lure than an exploit. A PDF can carry JavaScript, embedded files or exploit code for a reader bug, and it can also hold links or QR codes that lead to phishing or malware downloads.

pdfid is a small Python tool by Didier Stevens that counts key PDF keywords, such as /JavaScript, /OpenAction and /Launch. It gives a fast first look at whether a file contains features commonly abused by malware.

Be careful. Uploaded files can be accessed by others, so do not upload confidential documents. Searching by hash is safer because it only checks whether the file is already known without sharing its contents.

No. Many malicious PDFs have no script and rely on links, QR codes or social engineering. Check every URL, view the rendered page content in a safe way and consider where the file came from.

Record its hash, URLs and findings, report it to your security team, block the indicators, search for other recipients and remove the message. Do not simply delete the file, because evidence helps protect others.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.