Rundll32.exe Remote UNC/HTTP or Non-Standard DLL Load (LOLBAS)

Detects the execution of rundll32.exe with arguments pointing to remote UNC paths, HTTP/FTP URLs, or local DLL files residing outside of standard, trusted Windows system directories (System32/SysWOW64). This behavior is indicative of an attempt to proxy malicious code execution, commonly associated with fileless or remote payload retrieval techniques.