The malicious script executed in the Run dialog appeared legitimate, containing what looked like a verification comment—but was actually downloading and executing malicious files in the background using inbuilt Windows utilities such as ‘PowerShell’ and 'mshta'.