Odbcconf

T1218.008

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads. Odbcconf.exe is a Windows utility that allows you to configure Open Database Connectivity (ODBC) drivers and data source names. The Odbcconf.exe binary may be digitally signed by Microsoft.

Adversaries may abuse odbcconf.exe to bypass application control solutions that do not account for its potential abuse. Similar to Regsvr32, odbcconf.exe has a REGSVR flag that can be misused to execute DLLs (ex: odbcconf.exe /S /A {REGSVR "C:\Users\Public\file.dll"}).

Detection rules11

Rules on DetectionCode tagged with T1218.008.

Sigma8

RuleLevelLog source
Odbcconf.EXE Suspicious DLL Locationhighwindows / process_creation
Potentially Suspicious DLL Registered Via Odbcconf.EXEhighwindows / process_creation
Suspicious Driver/DLL Installation Via Odbcconf.EXEhighwindows / process_creation
Suspicious Response File Execution Via Odbcconf.EXEhighwindows / process_creation
Driver/DLL Installation Via Odbcconf.EXEmediumwindows / process_creation
New DLL Registered Via Odbcconf.EXEmediumwindows / process_creation
Response File Execution Via Odbcconf.EXEmediumwindows / process_creation
Uncommon Child Process Spawned By Odbcconf.EXEmediumwindows / process_creation

Splunk3

RuleTypeRiskData source
Windows Odbcconf HuntingHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Odbcconf Load DLLTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Odbcconf Load Response FileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups1

Software2

Campaigns0

None recorded.

Procedure examples3

Groups1

Used byProcedure example
GroupCobalt Group

Cobalt Group has used odbcconf to proxy the execution of malicious DLL files.

Software2

Used byProcedure example
MalwareBumblebee

Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts.

MalwareRaspberry Robin

Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the regsvr flag to execute DLLs and bypass application control mechanisms that are not monitoring for odbcconf.exe abuse.

References4

  1. LOLBAS Odbcconf Open source
    LOLBAS. (n.d.). Odbcconf.exe. Retrieved March 7, 2019.
  2. Microsoft odbcconf.exe Open source
    Microsoft. (2017, January 18). ODBCCONF.EXE. Retrieved March 7, 2019.
  3. TrendMicro Cobalt Group Nov 2017 Open source
    Giagone, R., Bermejo, L., and Yarochkin, F. (2017, November 20). Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks. Retrieved March 7, 2019.
  4. TrendMicro Squiblydoo Aug 2017 Open source
    Bermejo, L., Giagone, R., Wu, R., and Yarochkin, F. (2017, August 7). Backdoor-carrying Emails Set Sights on Russian-speaking Businesses. Retrieved March 7, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.