CRPx0 ClickFix Execution via Win+R RunMRU Registry Paste
Detects evidence of CRPx0 ClickFix ransomware execution by monitoring the HKCU RunMRU registry key for patterns indicating the execution of obfuscated or malicious commands (PowerShell, curl, or base64 encoded strings) consistent with clipboard-hijacking social engineering campaigns.
YARA-L

