rundll32.exe Executing DLL Payload from WebDAV UNC Share

Detects the execution of rundll32.exe from a WebDAV network path ('@\DavWWWRoot\') where specific suspicious substrings (e.g., 'verification.google', 'pf.ch', 'moor', 'CfgInspectModuleData') are present in the command line. This pattern is commonly associated with the execution of remote payloads or malicious DLLs to bypass security controls.