Often reaches out to compromised legitimate websites or dedicated domains like *.cloudapp.net .
Malicious shortcuts that execute PowerShell commands. CHM Files: Compiled HTML Help files used to drop backdoors.
Educate staff on the risks of opening unsolicited archives, even if the topic seems relevant.
