Suspicious Creation with Colorcpl

 Original Source: [Sigma source]
Title: Suspicious Creation with Colorcpl
Status: test
Description:Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
References:
  -https://twitter.com/eral4m/status/1480468728324231172?s=20
Author: frack113
Date: 2022-01-21
modified:2023-01-05
Tags:
  • -'attack.stealth'
  • -'attack.t1564'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith: '\colorcpl.exe'
  filter_ext:
    TargetFilename|endswith:
      -'.icm'
      -'.gmmp'
      -'.cdmp'
      -'.camp'

  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: high