Touch - Of Soul.zip
Searching for Event ID 4624 (Logon) or 4688 (Process Creation) to map the timeline of the attack.
Examining keys like HKCU\Software\Microsoft\Windows\CurrentVersion\Run for suspicious entries. Touch of Soul.zip
Inside the ZIP, investigators often find a shortcut ( .lnk ) or an executable ( .exe ) masked with a double extension (e.g., Touch of Soul.mp3.exe ). Searching for Event ID 4624 (Logon) or 4688