Explorer-Initiated Remote HTA Execution via MSHTA

Detects mshta.exe launched from Windows Explorer to retrieve remote HTA content over HTTP, a technique frequently observed in phishing campaigns and initial access attacks.