ClickFix social engineering attack

SE_CLICKFIX

← All detection heuristics · Social Engineering

high SE_CLICKFIX

What it means

Document instructs the user to press Win+R and paste or run a command.

Why it fires

ClickFix lures ask the user to open the Run dialog or a shell and paste a command, usually PowerShell or cmd. The rule looks for those instructions in document text. It is high-risk because the command is supplied by the lure, not because an exploit is present.

Other Social Engineering heuristics

SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY