Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org
Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads. Odbcconf.exe is a Windows utility that allows you to configure Open Database Connectivity (ODBC) drivers and data source names. The Odbcconf.exe binary may be digitally signed by Microsoft.
Adversaries may abuse odbcconf.exe to bypass application control solutions that do not account for its potential abuse. Similar to Regsvr32, odbcconf.exe has a REGSVR flag that can be misused to execute DLLs (ex: odbcconf.exe /S /A {REGSVR "C:\Users\Public\file.dll"}).
Rules on DetectionCode tagged with T1218.008.
| Rule | Level | Log source |
|---|---|---|
| Odbcconf.EXE Suspicious DLL Location | high | windows / process_creation |
| Potentially Suspicious DLL Registered Via Odbcconf.EXE | high | windows / process_creation |
| Suspicious Driver/DLL Installation Via Odbcconf.EXE | high | windows / process_creation |
| Suspicious Response File Execution Via Odbcconf.EXE | high | windows / process_creation |
| Driver/DLL Installation Via Odbcconf.EXE | medium | windows / process_creation |
| New DLL Registered Via Odbcconf.EXE | medium | windows / process_creation |
| Response File Execution Via Odbcconf.EXE | medium | windows / process_creation |
| Uncommon Child Process Spawned By Odbcconf.EXE | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Odbcconf Hunting | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Odbcconf Load DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Odbcconf Load Response File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupCobalt Group | Cobalt Group has used |
| Used by | Procedure example |
|---|---|
| MalwareBumblebee | Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts. |
| MalwareRaspberry Robin | Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.