CRPx0 VM/Sandbox Discovery via WMI Before Payload Detonation
Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.
YARA-L

