Rundll32 Proxy Execution via URL, JavaScript, or Shell32/URL.dll

Detects the use of rundll32.exe to execute code via remote URLs, JavaScript, or specific DLL functions known to be abused for proxy execution. This behavior is commonly associated with fileless malware and living-off-the-land techniques to bypass security controls by utilizing legitimate Windows binaries.