Would be kinda cool if they just spotted that it contained a full LISP interpreter and assumed from that that it might be malicious because in some earlier case they came across a malicious PDF that obscured its payload with a custom LISP interpreter.
These days, it's common for antivirus to flag software as malicious because it looks unfamiliar. This one may have flagged the PDF as malicious because it contains something resembling source code, but the virus scanner cannot identify the code.