RunDLL32 Remote UNC Path, JavaScript Protocol, or ShellExec_RunDLL Abuse

Detects instances of rundll32.exe being executed with command-line arguments that suggest malicious activity, specifically loading modules from remote UNC paths, using the javascript: protocol, or explicitly invoking ShellExec_RunDLL via shell32.dll. This rule filters out legitimate signed Microsoft binaries to focus on potentially unauthorized or malicious proxies.