ClickFix RunMRU registry write with PowerShell/curl/base64 command
Detects suspicious command-line entries within the Windows RunMRU registry key, which logs recently executed commands from the Run dialog (Win+R). This detection targets common ClickFix or copy-paste attack patterns, specifically identifying the presence of 'powershell', 'curl', or long base64-encoded strings.
YARA-L

