NotPetya-style wiper: rundll32 admin-share write + WMI remote exec

Detects coordinated activity indicative of destructive malware propagation similar to NotPetya. The rule identifies a three-stage sequence on a single host: execution of a DLL via rundll32.exe, followed by file writes to administrative network shares (C$/ADMIN$), and remote process creation via WMI (WmiPrvSE.exe), correlated with a high volume of SMB connections.