CRPx0 ClickFix Hidden-Window Base64 PowerShell from explorer.exe
Detects the execution of hidden, base64-encoded PowerShell commands spawned directly from explorer.exe, a pattern observed in the CRPx0 ClickFix campaign where attackers trick users into pasting malicious commands into the Windows Run dialog.
YARA-L

