Title:
Potentially Suspicious Rundll32.EXE Execution of UDL File
Status:
test
Description:Detects the execution of rundll32.exe with the oledb32.dll library to open a UDL file.
Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
References:
-https://trustedsec.com/blog/oops-i-udld-it-again
Author: @kostastsale
Date: 2024-08-16
modified:None
Tags:
- -'attack.execution'
- -'attack.command-and-control'
- -'attack.stealth'
- -'attack.t1218.011'
- -'attack.t1071'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_parent:
ParentImage|endswith:
'\explorer.exe'
selection_img:
Image|endswith:
'\rundll32.exe'
OriginalFileName:
'RUNDLL32.EXE'
selection_cli:
CommandLine|contains|all:
-'oledb32.dll'
-',OpenDSLFile '
-'\\Users\\*\\Downloads\\'
CommandLine|endswith:
'.udl'
condition:
all of selection_*
Falsepositives:
-UDL files serve as a convenient and flexible tool for managing and testing database connections in various development and administrative scenarios.
Level:
medium