Часто задаваемые вопросы
Does the analyzer open or execute the PDF?
No. It never embeds, renders or executes the document. It reads bytes and decompresses only supported, bounded streams for static inspection.
Does a LOW result prove that a PDF is safe?
No. Static browser analysis cannot prove safety or replace a maintained antivirus, sandbox or expert review. Encryption, unsupported filters, malformed objects and novel exploits can hide behavior.
Can a normal PDF contain flagged features?
Yes. Forms, links, embedded files and JavaScript can have legitimate uses. Findings describe attack surface and evidence; they are not by themselves a malware verdict.
What does the scanner look for?
It checks JavaScript and automatic-action markers, Launch/URI/GoTo/SubmitForm/ImportData actions, XFA and XML entities, embedded files, RichMedia, suspicious external or UNC paths, script network APIs, obfuscation indicators, encryption, object streams and data after the last EOF marker.