Potentially Suspicious Rundll32.EXE Execution of UDL File
Description
Detects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
Query · sigma
selection_parent: ParentImage|endswith: \explorer.exe selection_img: - Image|endswith: \rundll32.exe - OriginalFileName: RUNDLL32.EXE selection_cli: CommandLine|contains|all: - oledb32.dll - ',OpenDSLFile ' - \\Users\\*\\Downloads\\ CommandLine|endswith: .udl condition: all of selection_*
Known false positives
- UDL files serve as a convenient and flexible tool for managing and testing database connections in various development and administrative scenarios.