Mshta.exe Executing Remote HTA, javascript:, or vbscript Payload

Detects the execution of mshta.exe with suspicious command-line arguments that indicate the loading of remote HTML Applications (HTA) via URLs or inline scripts (javascript/vbscript). This behavior is often indicative of fileless malware execution and living-off-the-land techniques to bypass security controls.