I have an HTA the has two drop down lists. The first list values are created automatically when the HTA file loads using a vbscript subscript that connects to AD via LDAP and creates a list of OU's ...
The campaign exploits an Office vulnerability to deliver the modular XWorm RAT, chaining HTA, PowerShell, and in-memory .NET execution to sidestep detection and expand post-compromise control.
This is an undesirable program. This file has been identified as a program that is undesirable to have running on your computer. This consists of programs that are misleading, harmful, or undesirable.