CRPx0 rundll32 DLL invocation via numeric ordinal export
Detects execution of rundll32.exe using ordinal-based export calling syntax to load suspicious DLLs (e.g., sys_<hex>.dll) or reference non-executable files (e.g., WindowsUpdate.log). This behavior is consistent with the CRPx0 Stage 2 stager, which typically exports crypto globals and lacks standard named exports.
YARA-L

