New DLL Registered Via Odbcconf.EXE

 Original Source: [Sigma source]
Title: New DLL Registered Via Odbcconf.EXE
Status: test
Description:Detects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.
References:
  -https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16
  -https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/
  -https://redcanary.com/blog/raspberry-robin/
  -https://web.archive.org/web/20191023232753/https://twitter.com/Hexacorn/status/1187143326673330176
  -https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/
  -https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html
Author: Kirill Kiryanov, Beyu Denis, Daniil Yugoslavskiy, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-22
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218.008'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\odbcconf.exe' OriginalFileName:'odbcconf.exe'   selection_cli:
    CommandLine|contains|all:
      -'REGSVR '
      -'.dll'

  condition:all of selection_*
Falsepositives:
  -Legitimate DLLs being registered via "odbcconf" will generate false positives. Investigate the path of the DLL and its content to determine if the action is authorized.
Level: medium