ClickFix clipboard-paste PowerShell/mshta execution via Run dialog
Detects instances where Windows Explorer (explorer.exe) launches common script interpreters like PowerShell or mshta, often indicative of a 'ClickFix' social engineering attack where a user is coerced into pasting malicious commands into the Windows Run dialog.
YARA-L

