: Immediately disconnect any machine where this file was detected from the network.

: Check for related malicious processes or scheduled tasks that may have been established after the archive was extracted.

: The actor uses the command tar -xvf svchost.rar to extract post-compromise tools.