← All Tools

PDF Scanner

Check a suspicious PDF before you open it: antivirus scan, sandbox analysis of hidden links, JavaScript, programs and embedded files, and a safe preview of every page.

⚠ Read the result as evidence, not a guarantee. An antivirus detection, a blocklisted address, a Launch action or an embedded program is conclusive. Everything else is an indicator: scripts and forms are also used by honest documents (tax forms, for example). A clean result does not prove the content is honest; a fake invoice can be a perfectly clean file.
Where your file goes. The PDF is sent to this server (Germany), scanned in memory with ClamAV, then analysed on a separate sandbox server in a throwaway container that has no network access and is deleted after the scan. Nothing is stored, logged or shared with third parties. The SHA-256 hash is computed in your browser first, so you can look the file up on VirusTotal by its hash without uploading it anywhere.

What the scan checks

  • Antivirus: ClamAV signatures, on the PDF and on every file embedded in it.
  • Hidden programs: Launch actions (the PDF asks the reader to start a program such as cmd.exe or PowerShell) and embedded files whose real type is a program, script, macro document or disk image, whatever their name says.
  • JavaScript: every script, including those triggered when the document or a page opens. Scripts run in an emulated Acrobat environment in the sandbox; the tool records the web addresses they open, the data they send and the files they try to start, and unpacks obfuscated code (eval, unescape). Known exploit patterns (heap spray, old Reader CVEs) are flagged.
  • Links: every web address in link areas, actions, scripts, forms and the text, checked against local copies of the URLhaus, OpenPhish and Phishing Army blocklists. Page-sized or invisible links are flagged: a fake “View document” page where any click opens a phishing site is the most common malicious PDF.
  • File tricks: obfuscated keywords (/J#61vaScript), content left in old revisions, data hidden before the header or after the end of the file, password protection that blocks scanners.

Built on qpdf and poppler (the PDF engine of most Linux readers), plus a tolerant parser for damaged files, in the spirit of Didier Stevens’ pdfid and pdf-parser. The sandbox never connects anywhere, so it cannot see what a linked page contains: check suspicious addresses with the Phishing Checker.