This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
New DLL Registered Via Odbcconf.EXE
Original Source:
[Sigma source]
Title:
New DLL Registered Via Odbcconf.EXE
Status:
test
Description:
Detects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.
References:
-https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16
-https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/
-https://redcanary.com/blog/raspberry-robin/
-https://web.archive.org/web/20191023232753/https://twitter.com/Hexacorn/status/1187143326673330176
-https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/
-https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html
Author:
Kirill Kiryanov, Beyu Denis, Daniil Yugoslavskiy, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date:
2023-05-22
modified:
None
Tags:
-'attack.stealth'
-'attack.t1218.008'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\odbcconf.exe'
OriginalFileName
:
'odbcconf.exe'
selection_cli:
CommandLine|contains|all
:
-'REGSVR '
-'.dll'
condition
:
all of selection_*
Falsepositives:
-Legitimate DLLs being registered via "odbcconf" will generate false positives. Investigate the path of the DLL and its content to determine if the action is authorized.
Level:
medium