Exactly, the amateur image don't match with a sophisticated RAT.
If it has some amateur malware the AV will delete the file, if it was some kind of password stealer it will not set an image, if it was a sophisticated RAtT you will have a black image demand bitcoin to unlock the files.
The image don't match with sophisticated malware.
I will not lose too much time with it.