ClickFix: msiexec installs remote MSI via passive install spawned from explorer.

Detects the execution of msiexec.exe to install an MSI package from a remote URL. This pattern involves the Windows Installer utility being invoked by explorer.exe with the /i (install) and /passive (unattended installation) flags, indicating a potentially malicious download and execution chain often used to deliver payloads via social engineering.