Possible mshta.exe Remote .hta Payload Download (SideCopy LNK Chain)
Detects HTTP GET requests for files with a .hta extension, utilizing a legacy Internet Explorer User-Agent string. This pattern is commonly associated with SideCopy threat group activities where mshta.exe is used to proxy the execution of remotely hosted malicious HTA files, often as part of an initial infection chain.
Suricata

