Potential ClickFix Execution Pattern - Registry

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects potential ClickFix malware execution patterns by monitoring registry modifications in RunMRU keys containing HTTP/HTTPS links.

Severity

Trouble

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Swachchhanda Shrawan Poudel (Nextron Systems)