Docuboxer
By Sergio Alonzo Piña··6 min read

Can a PDF contain a virus? What to actually look for

PDFs can carry JavaScript, auto-run actions and embedded files. What each marker means, when it's legitimate, and how to inspect one without uploading it.

Yes — a PDF can carry executable content, and the format was designed that way. The specification allows embedded JavaScript, actions that fire the moment you open the file, requests to launch external programs, whole files attached inside the document, and even nested PDFs. None of that is malicious by default; the fillable form your accountant sent you uses some of it. But it is why a PDF attachment is a favorite delivery vehicle for phishing and malware. The practical upside: every one of those capabilities leaves a named marker in the file structure, and you can inspect a suspicious PDF without opening it right in your browser.

The markers that matter

Under the hood a PDF is a graph of objects with named keys. Only a handful of those keys grant the ability to do something rather than show something:

  • /JS and /JavaScript — embedded script. It is a restricted dialect, not browser JavaScript, but it can manipulate the document, read form fields and ask the reader application to act.
  • /OpenAction — what happens on open, before you touch anything. Harmless uses exist (jump to a bookmark, set the zoom). Pointed at script, it means code runs without a single click.
  • /AA (Additional Actions) — event handlers: on close, on print, on entering or leaving a field, on mouse-over. A convenient way to delay execution until after you have decided the file looks fine.
  • /Launch — asks the reader to run a program or open an external file. Modern readers block it or demand explicit confirmation, and almost no ordinary business document has a reason to include it.
  • /EmbeddedFile — a complete file stored inside the PDF. Sometimes it is the spreadsheet behind a report. Sometimes it is the payload the attacker needs you to double-click yourself.
  • /GoToE — "go to embedded": navigation into a PDF nested inside the PDF. Wrapping content this way is a known trick for slipping past shallow inspection.
  • /URI — external links. They execute nothing, and they are still the core of most PDF phishing: the document is clean, the branded "View invoice" button is not.

When these are completely normal

Skipping this part is how people end up treating every attachment as malware. Plenty of legitimate documents use these features:

  • Fillable forms. Tax forms, W-9s, claim forms, purchase orders — JavaScript validates a field, computes a total, or blocks submission when something is missing.
  • Report packages. A technical report may attach the source CSV as an /EmbeddedFile; archival PDF/A files embed fonts and attachments by design.
  • Presentations and manuals. An /OpenAction that opens the file in full-screen mode or at a specific chapter is a design choice, not an attack.
  • Structured e-invoices. Several invoicing standards ship machine-readable XML embedded inside the human-readable PDF. The attachment is the point of the document.

So the rule is not "script equals bad." It is does this capability match what the document claims to be. A government form with scripting: coherent. A "shipping receipt" from an address you do not recognize, with an auto-run action and a ZIP inside it: not coherent.

The combinations worth stopping for

  • /OpenAction or /AA wired to /JavaScript — execution with zero clicks.
  • /Launch present at all.
  • An /EmbeddedFile that is executable or compressed (.exe, .js, .vbs, .zip) in a document that never mentions an attachment.
  • A two-page file with almost no visible text but a disproportionately complex object structure.
  • Link text that does not match the destination, or a domain one character off the real one.

The email carrying the file is evidence too. Before you touch the attachment, it is worth knowing what SPF, DKIM and DMARC say about the sender — a message that fails authentication outright makes the attachment question much easier to answer.

What modern readers have already shut down

Worth saying, so this reads as calibration rather than scare copy: 2010 is not 2026. Adobe Acrobat Reader runs its JavaScript inside Protected Mode, lets you switch scripting off entirely in Preferences, and blocks by default the actions that try to launch a program or reach the network unprompted. The viewers built into Chrome and Firefox go further — a minimal subset of PDF JavaScript, no /Launch equivalent at all, and the whole parser inside the browser sandbox.

The takeaway is not that PDFs stopped being dangerous. It is that the dominant vector moved: less silent execution, more social engineering. The document that talks you into clicking the link, opening the attachment yourself or typing your password into a cloned login page works just as well against a hardened reader.

How to inspect it without opening or uploading it

Because the markers sit in the file structure rather than the rendered page, they can be read without rendering anything and without executing document content. That is what the local PDF scanner does: it parses the structure in your browser, lists the markers it finds, and the file never leaves your machine. That last part matters more than it sounds — the suspicious PDF is often a payslip, a contract or a medical letter, and "upload it to a stranger's server to find out if it is safe" is a poor trade.

If the attachment is not actually a PDF, start one step earlier. Extensions are trivially renamed; the leading bytes of a file are not. The file inspector compares the claimed extension against the real type. And PDF metadata often tells you which software produced the document and when, which is a quiet way to catch a fake that claims to come from a large company but was generated by an online form builder yesterday.

What this does not tell you

Being blunt here is more useful than being reassuring: listing markers is not antivirus, and "no dangerous markers" does not mean "safe". Three concrete reasons:

  • Exploits need no markers. A large share of real PDF attacks never use JavaScript. They feed malformed fonts, images or streams to the reader and exploit the parsing bug. There is no tidy named key for that.
  • Names can be obfuscated. PDF name syntax permits hex escapes, so /JavaScript can be written with some characters encoded and remain perfectly valid to the reader while defeating a naive literal search.
  • A link is just a link. The most effective PDF phishing carries no code at all. Structure comes back clean and the danger is entirely in the destination domain.

What you do get is decision-grade information in seconds. Knowing a file contains /Launch plus an embedded executable is enough to stop, and you learned it without opening the document.

A workable process for a suspicious attachment

  1. Do not open it yet in your system's default viewer.
  2. Look at the structure with a local scanner and note which markers appear.
  3. Verify the sender out of band. Thirty seconds on the phone defeats most impersonation, and no file analysis competes with that.
  4. If you must read it, use a viewer that renders pages without running scripts or opening attachments — the in-browser PDF reader shows the pages with nothing to install.
  5. Keep your reader updated. Against reader exploits, patches beat inspection every time.

The short version: PDFs can run code, usually for legitimate reasons, and knowing how to look inside turns a blind decision into an informed one. Informed is not the same as risk-free, and pretending otherwise is how people get caught.

Frequently asked questions

Can a PDF really contain a virus?

A PDF is a document, not an executable, so it cannot infect a machine just by existing. But the format allows embedded JavaScript, actions that fire the moment the file opens, and complete files attached inside the document — including executables. Most real-world damage comes from one of two things: you being talked into opening the embedded file or the link, or the PDF triggering a flaw in your PDF reader.

What does /OpenAction mean in a PDF?

/OpenAction is the document entry that says what should happen the instant the file opens, with no user interaction. Legitimately it jumps to a page or sets the zoom level. When /OpenAction points at JavaScript or a launch action, that is one of the clearest reasons to treat the file with suspicion.

Is JavaScript in a PDF always a red flag?

No. Interactive forms rely on it — field validation, calculated totals, date formatting. Tax forms, insurance claim forms and purchase orders routinely ship with JavaScript. The useful question is whether the code fits what the document claims to be. A fillable government form with scripting is normal; a two-page invoice from a stranger with an auto-run script is not.

How do I check a PDF without opening it?

The markers live in the file structure, not in the rendered page, so they can be read without drawing the document or running anything in it. Docuboxer's PDF scanner does that in your browser: it walks the structure, lists what it finds, executes nothing from the file, and never uploads it to a server.

If the scan finds nothing dangerous, is the PDF safe?

No, and anyone telling you otherwise is overselling. Structural inspection is not antivirus. It cannot catch exploits that target the reader's font, image or stream parsing, and PDF name syntax allows hex escapes, so a marker can be spelled in ways a literal search misses. No findings means no findings — not a clean bill of health.

What should I do with a PDF I don't trust?

Do not open it on your main machine. Verify the sender through a different channel — a phone call or a message on another app beats any technical check for impersonation. At work, forward it to your security team as-is rather than passing it around. If you must read it, use a viewer that renders pages without running JavaScript or opening attachments, and keep your reader patched.

See what is inside that PDF

JavaScript, auto-run actions and embedded files, listed in your browser. The file is never uploaded.

Scan a PDF →

Related tools

You might also like: what PDF metadata reveals about a document.