Embedded PE launches remote HTA

HWP_PE_MSHTA_REMOTE_EXEC

← All detection heuristics · HWP

critical HWP_PE_MSHTA_REMOTE_EXEC

What it means

The HWP's packaged PE invokes mshta with a remote URL.

Why it fires

The packaged executable invokes mshta with a remote URL. This command causes mshta to retrieve and execute the referenced HTA or script content.

Other HWP heuristics

HWP_EMBEDDED_PE HWP_OLE_PACKAGE_EXECUTABLE HWP_OLE_CLICK_TO_EXEC_LURE HWP_PS_EXEC HWP_PS_CVX_EXEC HWP_PS_SYSTEM HWP_SHELL_CMD HWP_POSTSCRIPT HWP_PS_HEXCODE HWP_JAVASCRIPT HWP_PS_FILE HWP_URL HWP_PS_FILTER HWP_SCRIPTS_STREAM HWP_BINDATA HWP_COMPRESSED HWP_SEMANTIC_FINGERPRINT HWP_STREAM_RAW_FALLBACK