Suspicious MSHTA execution via HTML smuggling

Identifies suspicious execution of mshta process initiated by a web browser as part of an HTML smuggling attack chain. This behavior is strongly associated with multi-stage malware delivery and execution via phishing-driven HTML smuggling.

Back to all rules