• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    ClickFix msiexec Run-dialog remote MSI install spawned by explorer.exe

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 9 days ago•0•0•2

    Detects the 'ClickFix' social engineering pattern where an adversary tricks a user into using the Windows Run dialog (explorer.exe) to execute msiexec.exe, downloading and installing a remote MSI package. This is frequently associated with malware delivery, such as Psychedelic Stealer, where users are prompted to copy and paste malicious commands under the guise of fake error messages or CAPTCHAs.

    YARA-L

    Tags

    T1204.004 - Malicious Copy and PasteT1218.007 - MsiexecTA0002 - ExecutionTA0005 - StealthProcess CreationCommand ExecutionWindowsWindows SysmonWindows Eventlog Security

    Found in

    • Psychedelic Stealer Campaign Targeting Ukraine via ClickFixLast updated 11 days ago
    • Psychedelic Stealer Campaign Targeting Ukraine via ClickFixLast updated 11 days ago
    • Psychedelic Stealer Campaign Targeting Ukraine via ClickFixLast updated 11 days ago
    • Psychedelic Stealer Campaign Targeting Ukraine via ClickFixLast updated 11 days ago
    • Psychedelic Stealer Campaign Targeting Ukraine via ClickFixLast updated 11 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?