PE executable found inside HWP document.
The HWP's packaged PE invokes mshta with a remote URL.
An HWP BinData OLE Package carries a valid Windows executable under an executable filename.
The HWP body links a temporary-path executable to an embedded OLE Package carrying the same filename.
PostScript 'exec' operator found in embedded PostScript.
PostScript hex string converted to executable code and executed at runtime.
PostScript 'system' operator found.
Reference to a shell command (cmd.exe, powershell, etc.) in HWP.
HWP document contains embedded PostScript or EPS content.
Many hex escape sequences found in PostScript content.
JavaScript references found in HWP document.
PostScript file operation (file/run/deletefile) found.
External URL(s) found in HWP document content.
PostScript decode filter (SubFileDecode, ASCIIHexDecode, etc.) found.
OLE-based HWP contains a Scripts storage section.
OLE-based HWP contains a BinData storage section.
Zlib-compressed sections were found and decompressed for analysis.
Stable digest of decompressed HWP logical stream names and content.
A payload-bearing stream did not inflate as raw DEFLATE and was scanned in its original form.