https://forensicitguy.github.io/hcrypt-injecting-bitrat-analysis/
HCrypt Injecting BitRAT using PowerShell, HTAs, and .NET - Tony Lambert