Analytics BIOC Low

Uncommon execution of ODBCConf

Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Odbcconf (T1218.008)
Attacker's goals:

Execute arbitrary code or load malicious DLL modules undetected within Microsoft signed program from Microsoft signed process.

Investigative actions:

Check the execution command-line, in case of 'REGSVR' points to a DLL, then check it. If the command-line contains '/f' argument (for script file) check the content of the script.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Uncommon execution of ODBCConf to load dll directly High (parent: Low)