Identifying the (GPS coordinates) of where the photo was taken (found via reverse image search or checking EXIF data).

Use the file command in Linux or a tool like TrID to confirm the file is actually a RAR archive and not a renamed extension (e.g., a JPEG with a .rar extension).

The password is frequently the date of birth or the handle of the individual featured in the "preview" image associated with the archive.

Look at the filename itself. "Candy-Tokyo" and "Teen" are keywords.