Invoke-Obfuscation Via Use Rundll32 - PowerShell Module — Detection Rule

Detects Obfuscated Powershell via use Rundll32 in Scripts

Read the full analysis on IntelFusions