ClickFix: PowerShell via Run dialog downloads from WebDAV
Detects the execution of PowerShell via explorer.exe (typically initiated through the Windows Run dialog) where the command line references a WebDAV UNC path (containing DavWWWRoot). This behavior is characteristic of 'ClickFix' social engineering attacks, where users are coerced into copying and pasting commands into the Run dialog that trigger remote script execution.
YARA-L

