Use a robust EDR (Endpoint Detection and Response) tool to identify the persistence mechanism.
The downloaded file is LatinDogStyle.7z . Attackers use .7z or .rar formats because they are less frequently scanned by basic email gateways compared to .zip files.
It detects when the user navigates to a banking website and displays a fake, identical-looking pop-up window to steal passwords and 2FA codes.