: .ps1 , .bat , or .js files which may be used as infection vectors.
: Generate MD5, SHA-1, and SHA-256 hashes to check against threat intelligence platforms like VirusTotal .
: Verify the file is a true ZIP archive by checking for the header signature 50 4B 03 04 .