• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    CRPx0 ClickFix Execution via Win+R RunMRU Registry Paste

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 26 days ago•0•0•8

    Detects evidence of CRPx0 ClickFix ransomware execution by monitoring the HKCU RunMRU registry key for patterns indicating the execution of obfuscated or malicious commands (PowerShell, curl, or base64 encoded strings) consistent with clipboard-hijacking social engineering campaigns.

    YARA-L

    Tags

    T1204 - User ExecutionT1059.001 - PowerShellT1112 - Modify RegistryTA0002 - ExecutionTA0003 - PersistenceRegistry Value SetRegistry Value ModificationCommand ExecutionScript ExecutionWindowsWindows Sysmon

    Found in

    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?