Suspicious Creation with Colorcpl (e15b518d-b4ce-4410-a9cd-501f23ce4a18)
Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Suspicious Creation with Colorcpl (e15b518d-b4ce-4410-a9cd-501f23ce4a18) | Sigma-Rules | Hide Artifacts - T1564 (22905430-4901-4c2a-84f6-98243cb173f8) | Attack Pattern | 1 |