ClickFix msiexec launched from Explorer Run dialog with ORG_NOTE decoy property

Detects execution of msiexec.exe via the Windows Run dialog (launched by explorer.exe) that utilizes a remote URL for an MSI installer alongside suspicious property flags ('ORG_NOTE', 'passive'). This pattern is associated with 'ClickFix' social engineering campaigns where users are instructed to copy-paste commands to 'fix' a display issue, leading to the execution of malicious installers.