: Immediately disconnect any machine where this file was detected from the network.
: Check for related malicious processes or scheduled tasks that may have been established after the archive was extracted.
: The actor uses the command tar -xvf svchost.rar to extract post-compromise tools.