This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Creation with Colorcpl
Original Source:
[Sigma source]
Title:
Suspicious Creation with Colorcpl
Status:
test
Description:
Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
References:
-https://twitter.com/eral4m/status/1480468728324231172?s=20
Author:
frack113
Date:
2022-01-21
modified:
2023-01-05
Tags:
-'attack.stealth'
-'attack.t1564'
Logsource:
product: windows
category: file_event
Detection:
selection:
Image|endswith
:
'\colorcpl.exe'
filter_ext:
TargetFilename|endswith
:
-'.icm'
-'.gmmp'
-'.cdmp'
-'.camp'
condition
:
selection and not 1 of filter_*
Falsepositives:
-Unknown
Level:
high