CRPx0 Stage 2 DLL Ordinal Invocation via rundll32 WindowsUpdate.log
Detects the execution of the CRPx0 ransomware Stage 2 stager DLL via rundll32.exe. The attack leverages ordinal-based invocation (exporting crypto globals rather than named functions) and masquerades the malicious DLL as a system file named 'WindowsUpdate.log'.
Sigma

