Suspicious MSHTA execution via HTML smuggling
Identifies suspicious execution of mshta process initiated by a web browser as part of an HTML smuggling attack chain. This behavior is strongly associated with multi-stage malware delivery and execution via phishing-driven HTML smuggling.
- Platform: Windows
- Severity: High
- MITRE Tactic: Execution
- MITRE Techniques: T1204, T1204.001