Detects suspicious Rundll32 execution from control.exe as used by Equation Group and Exploit Kits
Read the full analysis on IntelFusions