Windows Process Execution: odbcconf.exe with DLL in Suspicious Path

Flags odbcconf.exe process launches when the command line references DLL-related paths in suspicious Windows locations.

FreeUnreviewedSigmahighv1
title: "Windows Process Execution: odbcconf.exe with DLL in Suspicious Path"
id: c12601fd-b992-4e10-8a67-bcb17dbc4182
status: test
description: This rule identifies executions of odbcconf.exe where the command line contains one of several directory paths considered potentially suspicious for DLL registration. Attackers can abuse legitimate Windows binaries like odbcconf.exe to load or register malicious DLLs from unusual locations to evade detection. The detection relies on Windows process creation telemetry, matching the process image/original filename and scanning the full command line for specific path patterns.
references:
  - https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16
  - https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html
  - https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_odbcconf_exec_susp_locations.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-05-22
modified: 2023-05-26
tags:
  - attack.stealth
  - attack.t1218.008
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \odbcconf.exe
    - OriginalFileName: odbcconf.exe
  selection_cli:
    CommandLine|contains:
      - :\PerfLogs\
      - :\ProgramData\
      - :\Temp\
      - :\Users\Public\
      - :\Windows\Registration\CRMLog
      - :\Windows\System32\com\dmp\
      - :\Windows\System32\FxsTmp\
      - :\Windows\System32\Microsoft\Crypto\RSA\MachineKeys\
      - :\Windows\System32\spool\drivers\color\
      - :\Windows\System32\spool\PRINTERS\
      - :\Windows\System32\spool\SERVERS\
      - :\Windows\System32\Tasks_Migrated\
      - :\Windows\System32\Tasks\Microsoft\Windows\SyncCenter\
      - :\Windows\SysWOW64\com\dmp\
      - :\Windows\SysWOW64\FxsTmp\
      - :\Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System\
      - :\Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter\
      - :\Windows\Tasks\
      - :\Windows\Temp\
      - :\Windows\Tracing\
      - \AppData\Local\Temp\
      - \AppData\Roaming\
  condition: all of selection_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: 6b65c28e-11f3-46cb-902a-68f2cafaf474
    type: derived

What it detects

This rule identifies executions of odbcconf.exe where the command line contains one of several directory paths considered potentially suspicious for DLL registration. Attackers can abuse legitimate Windows binaries like odbcconf.exe to load or register malicious DLLs from unusual locations to evade detection. The detection relies on Windows process creation telemetry, matching the process image/original filename and scanning the full command line for specific path patterns.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.