.. /Colorcpl.exe
Star

Copy

Binary that handles color management

Paths:

Resources:

Acknowledgements:

Detections:

Copy

  1. Copies the referenced file to C:\Windows\System32\spool\drivers\color\.

    colorcpl {PATH}
    Use case
    Copies file(s) to a subfolder of a generally trusted folder (c:\Windows\System32), which can be used to hide files or make them blend into the environment.
    Privileges required
    User
    Operating systems
    Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
    ATT&CK® technique
    T1036.005