Abstract
In the current context of rapid technological advancement, electronic documents are widely used across various domains. One of the most common formats of electronic documents is the PDF (Portable Document Format), which is utilized for creating, storing, and transmitting documents in a fixed-layout form. At the same time, the use of modern software tools for editing electronic documents creates opportunities for their falsification, in particular through document montage, including the insertion of textual fragments, alteration of document requisites, or their addition/modification prior to printing. This article addresses the detection of document montage in electronic and hybrid documents within the framework of a comprehensive approach involving both forensic document examination and computer forensic examination. Particular attention is paid to the examination of PDF files as one of the most widely used formats in contemporary document workflow. The study analyzes the possibilities of identifying text alterations, insertion or modification of individual requisites, and changes to graphical elements carried out in the digital environment prior to printing. The purpose of the study is to analyze contemporary approaches to the detection of document montage in electronic and hybrid documents through the application of methods of forensic document examination and computer forensic examination. The methodological basis of the research includes methods of analysis, generalization, and forensic examination of documents, in particular the analysis of graphical characteristics of text, document structure, and metadata of electronic files. The study identifies characteristic indicators of document montage that can be established both in the electronic PDF file and in the printed hard copy of the document. The conclusions. It is demonstrated that the combined application of computer forensic and forensic document examination methods enables effective detection of alterations introduced into a document prior to printing and enhances the evidential value and reliability of expert conclusions.
References
Casey E. (2018). Tsyfrovi dokazy ta kompiuterni zlochyny [Digital evidence and computer crime]. Kyiv: Yurinkom Inter. 528 p. [in Ukrainian].
Verkhovna Rada of Ukraine. (2003). Pro elektronni dokumenty ta elektronnyi dokumentoobih: Zakon Ukrainy vid 22.05.2003 № 851-IV [On electronic documents and electronic document management: Law of Ukraine dated 22.05.2003 No. 851-IV]. Vidomosti Verkhovnoi Rady Ukrainy, 36, 12 p. [in Ukrainian].
Shepitko V.Yu., Zhuravel V.A., Konovalova V.O. et al. (2019). Kryminalistyka: pidruchnyk: u 2 t. T. 1 [Criminalistics: textbook: in 2 vols. Vol. 1]. Shepitko V.Yu. (Ed.). Kharkiv: Pravo. 456 p. [in Ukrainian].
Bilous V.T. (2014). Kryminalistyka: navchalnyi posibnyk [Criminalistics: study guide]. Kyiv: Atika. 495 p. [in Ukrainian].
Klymenko N.I. (2017). Sudova ekspertyza dokumentiv [Forensic examination of documents]. Kyiv: Yurinkom Inter. 272 p. [in Ukrainian].
Simson L., Garfinkel S. (2010). Digital forensics research: The next 10 years. Digital Investigation, S64–S73. DOI: 10.1016/j.diin.2010.05.009 [in English].
Carrier B. (2005). File System Forensic Analysis. Boston: Addison-Wesley. 600 p. [in English].
Casey E. (2011). Digital Evidence and Computer Crime. Academic Press. 840 p. [in English].
Klymenko N.I., Pyrih I.V. (2015). Sudovo-ekspertni doslidzhennia dokumentiv [Forensic expert studies of documents]. Kyiv: KNDISE. 256 p. [in Ukrainian].
Shepitko V.Yu., Konovalova V.O. (2018). Kryminalistyka: metodolohiia ta praktyka [Criminalistics: methodology and practice]. Kharkiv: Pravo. 464 p. [in Ukrainian].
Peliushok V. H. Doslidzhennya dokumentiv, vyhotovlenykh tekhnichnym montazhem: metodychni rekomendatsiyi. [Examination of Documents Produced by Technical Montage: Methodological Recommendations]. Kyiv: State Research Forensic Center of the Ministry of Internal Affairs of Ukraine, 2022. 19 p. [in Ukrainian].
Whitington J. (2011). PDF Explained. O’Reilly Media, Inc. 140 p. URL: https://learning.oreilly.com/library/view/pdf-explained/9781449321581/ (accessed: 19.03.2026) [in English].
Rosenthol L. (2013). Developing with PDF. O’Reilly Media, Inc. 215 p. URL: https://learning.oreilly.com/library/view/developing-with-pdf/9781449327903/ (accessed: 19.03.2026) [in English].
Nissim N., Cohen A., Glezer C., Elovici Y. (2016). Detection of malicious PDF files and directions for enhancements. Computers & Security, 48, 239–248. DOI: 10.1016/j.cose.2014.10.014 [in English].
Afandi M., Amrulloh R., Isnaini K. N., Suhartono D. Analisis Forensik Pemalsuan Dokumen PDF Menggunakan Metode National Institute of Justice (NIJ). Jurnal Resistor. 2024. Vol. 7, № 3. P. 162–170. DOI: https://doi.org/10.31598/jurnalresistor.v7i3.1460.