File: Kill.the.plumber.zip ... -

Look for unusual .sh or .bat scripts in the startup folders of the extracted archive.

binwalk , strings , Autopsy or FTK Imager , Wireshark (if PCAPs are included), and ExifTool . 2. Initial Analysis File: Kill.The.Plumber.zip ...

Run file Kill.The.Plumber.zip to confirm it is a standard ZIP archive. Look for unusual