Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0486 — Detecting Odbcconf Proxy Execution of Malicious DLLs
DET0486

Detecting Odbcconf Proxy Execution of Malicious DLLs

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1335 Analytic 1335
Windows

Identifies abuse of odbcconf.exe to execute malicious DLLs using the REGSVR command flag. Behavior chain: (1) Process creation of odbcconf.exe with /REGSVR or /A {REGSVR ...} arguments → (2) DLL load by odbcconf.exe of non-standard or unsigned modules → (3) Optional follow-on process creation or network activity from loaded DLL.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=3, 22
[ParentProcessName] List of approved processes that may legitimately invoke odbcconf.exe
[AllowedCommandPatterns] Known-good odbcconf.exe arguments in the environment
[TimeWindow] Time range for correlating module loads and network activity after odbcconf.exe execution
[ApprovedModuleHashes] Baseline of legitimate DLLs loaded by odbcconf.exe

Detected Techniques

1

Details

MITRE ID
DET0486
STIX ID
x-mitre-detection-strategy--9407410b-7f35-4d32-be3c-e48ea36573d9
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.