Below is a structured write-up template based on standard forensic analysis of such a file. Filename: video_2020-12-22_20-56-26.7z Extension: .7z (7-Zip Compressed Archive) Format: LZMA or LZMA2 compression
Changes to Registry keys (Run/RunOnce) to ensure the malware starts on boot.
Upon decompressing the archive, investigators typically look for: