Analytics BIOC
Low
✕
Uncommon execution of ODBCConf
Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Odbcconf (T1218.008)
Attacker's goals:
Execute arbitrary code or load malicious DLL modules undetected within Microsoft signed program from Microsoft signed process.
Investigative actions:
Check the execution command-line, in case of 'REGSVR' points to a DLL, then check it. If the command-line contains '/f' argument (for script file) check the content of the script.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Uncommon execution of ODBCConf to load dll directly High (parent: Low)