← All detection heuristics · HWP
critical
HWP_PE_MSHTA_REMOTE_EXEC
What it means
The HWP's packaged PE invokes mshta with a remote URL.
Why it fires
The packaged executable invokes mshta with a remote URL. This command causes mshta to retrieve and execute the referenced HTA or script content.
Other HWP heuristics
HWP_EMBEDDED_PE HWP_OLE_PACKAGE_EXECUTABLE HWP_OLE_CLICK_TO_EXEC_LURE HWP_PS_EXEC HWP_PS_CVX_EXEC HWP_PS_SYSTEM HWP_SHELL_CMD HWP_POSTSCRIPT HWP_PS_HEXCODE HWP_JAVASCRIPT HWP_PS_FILE HWP_URL HWP_PS_FILTER HWP_SCRIPTS_STREAM HWP_BINDATA HWP_COMPRESSED HWP_SEMANTIC_FINGERPRINT HWP_STREAM_RAW_FALLBACK