Unusual outbound traffic to unknown IP addresses (often in Russia or Eastern Europe).
IP address, hardware ID, location, and screenshots of your desktop.
New folders in %AppData% or %LocalAppData% with random 8-character names.
From a different, clean device , change all passwords (Email, Banking, Discord).
Once the user extracts the RAR file, the typical infection flow is: