How to Detect and Analyze PDF Malware: A Beginner's Step-by-Step Method
Learn how to detect and analyze PDF malware using simple, beginner-friendly steps. PDF malware is a growing cyber threat where attackers embed malicious JavaScript, links, or files inside PDF documents. This guide explains how to set up a safe malware analysis environment, identify suspicious PDF characteristics, extract and analyze hidden JavaScript, review embedded files and links, perform static and dynamic analysis, and use free tools like pdfid.py, pdf-parser.py, VirusTotal, and CyberChef. The blog is designed for IT professionals, students, and cybersecurity beginners looking to develop hands-on malware analysis skills without needing advanced experience.
Quick answer: To analyse a suspicious PDF safely, work in an isolated virtual machine, never open it in a normal reader, hash the file, scan it with pdfid and look for risky keywords such as /JavaScript, /OpenAction, /Launch and /EmbeddedFile. Then inspect the objects with pdf-parser, extract links, and check indicators against threat intelligence.
Key takeaways
- Never open a suspect PDF on your main machine. Use an isolated VM with no shared folders and a snapshot.
- Triage first: hash, file type, then pdfid to count risky keywords.
- Risky markers include /JavaScript, /JS, /OpenAction, /AA, /Launch, /EmbeddedFile and /URI.
- Many malicious PDFs are phishing carriers with links or QR codes, not exploits. Check where links lead.
- Record hashes, URLs and findings, and report them; do not just delete the file.
Why are PDFs used to deliver malware?
PDF is trusted, widely shared and supports features beyond text: embedded JavaScript, forms, file attachments and links. Attackers use it in two main ways. The first is exploiting a bug in a PDF reader, which is less common today because readers are patched and sandboxed. The second, and more frequent, is using the PDF as a lure: it contains a link or a QR code that sends the victim to a phishing page or a malware download. A good analyst checks for both.
How do you set up a safe analysis environment?
- Use a virtual machine, for example a Linux VM, with a snapshot you can restore.
- Disable shared folders, clipboard sharing and drag and drop.
- Turn off the network, or place the VM on an isolated host-only network, unless you deliberately need to test a link in a controlled way.
- Install the analysis tools beforehand, because you will not have internet access during analysis.
- Do not open the PDF in a graphical reader. Analyse it as data using command-line tools.
What is the step-by-step workflow?
- Record the basics. Compute a hash so you can identify the file and look it up later.
Thesha256sum suspicious.pdf file suspicious.pdf exiftool suspicious.pdffilecommand confirms it really is a PDF, and exiftool shows metadata such as creator and dates. - Look up the hash. From your normal machine, search the hash on VirusTotal. Do not upload confidential documents, because uploaded files can be seen by others.
- Triage with pdfid. Didier Stevens'
pdfid.pycounts important keywords.
Read the counts forpython3 pdfid.py suspicious.pdf/JS,/JavaScript,/OpenAction,/AA,/Launch,/EmbeddedFile,/RichMediaand/URI. A normal one-page document usually has none of the first ones. - Inspect objects with pdf-parser. Search for the suspicious keyword and read the object around it.
Thepython3 pdf-parser.py --search javascript suspicious.pdf python3 pdf-parser.py --object 12 --filter --raw suspicious.pdf--filteroption decodes compressed streams so you can read the content. - Extract URLs and attachments. List
/URIentries and any embedded files. Defang URLs before putting them in notes, for examplehxxps://example[.]com. - Read any script as text. Obfuscated JavaScript often hides a download address or shellcode. Describe what it does; do not run it.
- Decide and document. Write the hashes, keywords found, URLs and your conclusion. Report to your security team or mail provider.
What do the keywords mean?
| Keyword | Meaning | Why it matters |
|---|---|---|
| /JavaScript, /JS | Embedded script | Can run code or hide exploit logic |
| /OpenAction, /AA | Action run when the file opens or an event occurs | Automatic execution trigger |
| /Launch | Start an external program | Rare in benign files |
| /EmbeddedFile | Attached file | May hide another malicious file |
| /URI | Link | Common in phishing lures |
| /Encrypt, odd filters | Encryption or stacked encodings | Used to evade scanners |
One keyword does not prove malice. Forms and legitimate business PDFs use JavaScript too. Look at combinations and at what the script does.
Worked scenario
This is an illustrative case, not a real incident. An employee gets an "invoice.pdf". The hash is unknown to VirusTotal. pdfid reports no JavaScript, no OpenAction, but one /URI and a large image. Opening the file as an image shows a QR code with the text "scan to view payment". Decoding the QR code in the VM reveals a link to a login-style page on an unrelated domain. Verdict: a phishing lure with no exploit. Actions: block the domain, remove the message from other mailboxes, and warn users about QR phishing.
Common mistakes
- Double-clicking the file "just to see".
- Uploading a confidential PDF to a public scanning site.
- Assuming no JavaScript means safe, forgetting links and QR codes.
- Running recovered scripts to see what happens.
- Forgetting that analysing real samples needs authorisation in a workplace.
Next steps
For more on scanning files and URLs, read VirusTotal explained and QR code phishing in PDFs. To learn analysis methods properly, see our CHFI forensics course or the SOC analyst course.
Related reading
- FBI Issues Urgent Warning | Stop Using Online File Converters – A Growing Cyber Threat for Chrome, Edge, and Safari Users
- FTP Search Engines | How Cybercriminals and Researchers Use FTP for Information Gathering and How to Secure FTP Servers
- Social Engineering – Part 2 | Computer-Based and Mobile-Based Attack Techniques (Plus Popular Tools)
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0