ClickFix Series: mshta.exe Execution From explorer.exe Under Fake CAPTCHA Lure
Detects the execution of mshta.exe with arguments pointing to remote URLs or containing JavaScript. This behavior is commonly associated with phishing campaigns where attackers use fake CAPTCHA lures to trick users into executing malicious scripts via mshta.exe, often launched directly from Windows Explorer (e.g., from a downloaded file).
Sigma

