: If you must inspect a suspicious file, do so in a virtual machine or a tool like Any.Run or VirusTotal to see its behavior without risking your host machine.

: Never download files from unknown senders, even if the filename seems relevant to your interests or work.

: The file is usually delivered via phishing emails or "social engineering" messages on platforms like Discord or Telegram. It often masquerades as a legitimate document or "leaked" content to entice users to click.