Rundll32 Network Activity Without DLL Parameters (Possible ACR Stealer)

Detects instances where rundll32.exe executes with missing or minimal DLL arguments and subsequently establishes outbound network connections. This behavior is uncommon in legitimate Windows operations and has been observed during ACR Stealer infections, including executions originating from remote SMB shares and memory-loaded payloads.