Technical reports from sandbox environments like Joe Sandbox and Any.Run show the following behavior when the file is opened:

: It checks for virtual machines or debuggers to see if a researcher is watching it.

: Multiple antivirus engines on VirusTotal flag this file and its contents as Trojan:Win32/Stealc or Lumma Stealer . These are "Infostealers" designed to harvest sensitive data from your computer.