{"id":"T1218.008","name":"Odbcconf","url":"https://attack.mitre.org/techniques/T1218/008","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0486","stix_id":"x-mitre-detection-strategy--9407410b-7f35-4d32-be3c-e48ea36573d9","name":"Detecting Odbcconf Proxy Execution of Malicious DLLs","url":"https://attack.mitre.org/detectionstrategies/DET0486","analytics":[{"id":"AN1335","stix_id":"x-mitre-analytic--6c0a2e08-debd-46e6-bb5f-5159ad8f12ad","name":"Analytic 1335","description":"Identifies abuse of odbcconf.exe to execute malicious DLLs using the REGSVR command flag. Behavior chain: (1) Process creation of odbcconf.exe with /REGSVR or /A {REGSVR ...} arguments → (2) DLL load by odbcconf.exe of non-standard or unsigned modules → (3) Optional follow-on process creation or network activity from loaded DLL.","url":"https://attack.mitre.org/detectionstrategies/DET0486#AN1335","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessName","description":"List of approved processes that may legitimately invoke odbcconf.exe"},{"field":"AllowedCommandPatterns","description":"Known-good odbcconf.exe arguments in the environment"},{"field":"TimeWindow","description":"Time range for correlating module loads and network activity after odbcconf.exe execution"},{"field":"ApprovedModuleHashes","description":"Baseline of legitimate DLLs loaded by odbcconf.exe"}],"live":true,"detection_strategies":["DET0486"],"techniques":["T1218.008"]}],"live":true,"version":"1.0","techniques":["T1218.008"]}],"sigma_rules":[{"id":"2d32dd6f-3196-4093-b9eb-1ad8ab088ca5","title":"Suspicious Response File Execution Via Odbcconf.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-05-22","modified":"2024-03-13","description":"Detects execution of \"odbcconf\" with the \"-f\" flag in order to load a response file with a non-\".rsp\" extension.","references":["https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/","https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml","techniques":["T1218.008"],"cves":[]},{"id":"3f5491e2-8db8-496b-9e95-1029fce852d4","title":"Driver/DLL Installation Via Odbcconf.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-22","modified":null,"description":"Detects execution of \"odbcconf\" with \"INSTALLDRIVER\" which installs a new ODBC driver. Attackers abuse this to install and run malicious DLLs.","references":["https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/","https://web.archive.org/web/20191023232753/https://twitter.com/Hexacorn/status/1187143326673330176","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_driver_install.yml","techniques":["T1218.008"],"cves":[]},{"id":"5f03babb-12db-4eec-8c82-7b4cb5580868","title":"Response File Execution Via Odbcconf.EXE","author":"Kirill Kiryanov, Beyu Denis, Daniil Yugoslavskiy, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-22","modified":"2024-03-05","description":"Detects execution of \"odbcconf\" with the \"-f\" flag in order to load a response file which might contain a malicious action.","references":["https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/","https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml","techniques":["T1218.008"],"cves":[]},{"id":"6b65c28e-11f3-46cb-902a-68f2cafaf474","title":"Odbcconf.EXE Suspicious DLL Location","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-05-22","modified":"2023-05-26","description":"Detects execution of \"odbcconf\" where the path of the DLL being registered is located in a potentially suspicious location.","references":["https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16","https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html","https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_exec_susp_locations.yml","techniques":["T1218.008"],"cves":[]},{"id":"8e3c7994-131e-4ba5-b6ea-804d49113a26","title":"Uncommon Child Process Spawned By Odbcconf.EXE","author":"Harjot Singh @cyb3rjy0t","status":"test","level":"medium","date":"2023-05-22","modified":null,"description":"Detects an uncommon child process of \"odbcconf.exe\" binary which normally shouldn't have any child processes.","references":["https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/","https://medium.com/@cyberjyot/t1218-008-dll-execution-using-odbcconf-exe-803fa9e08dac"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_uncommon_child_process.yml","techniques":["T1218.008"],"cves":[]},{"id":"9f0a8bf3-a65b-440a-8c1e-5cb1547c8e70","title":"New DLL Registered Via Odbcconf.EXE","author":"Kirill Kiryanov, Beyu Denis, Daniil Yugoslavskiy, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-22","modified":null,"description":"Detects execution of \"odbcconf\" with \"REGSVR\" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.","references":["https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/","https://redcanary.com/blog/raspberry-robin/","https://web.archive.org/web/20191023232753/https://twitter.com/Hexacorn/status/1187143326673330176","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_register_dll_regsvr.yml","techniques":["T1218.008"],"cves":[]},{"id":"ba4cfc11-d0fa-4d94-bf20-7c332c412e76","title":"Potentially Suspicious DLL Registered Via Odbcconf.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-05-22","modified":null,"description":"Detects execution of \"odbcconf\" with the \"REGSVR\" action where the DLL in question doesn't contain a \".dll\" extension. Which is often used as a method to evade defenses.","references":["https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/","https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_register_dll_regsvr_susp.yml","techniques":["T1218.008"],"cves":[]},{"id":"cb0fe7c5-f3a3-484d-aa25-d350a7912729","title":"Suspicious Driver/DLL Installation Via Odbcconf.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-05-23","modified":null,"description":"Detects execution of \"odbcconf\" with the \"INSTALLDRIVER\" action where the driver doesn't contain a \".dll\" extension. This is often used as a defense evasion method.","references":["https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/","https://web.archive.org/web/20191023232753/https://twitter.com/Hexacorn/status/1187143326673330176","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.008"],"path":"rules/windows/process_creation/proc_creation_win_odbcconf_driver_install_susp.yml","techniques":["T1218.008"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}