Colorcpl.exe

Binary that handles color management

Paths

  • C:\Windows\System32\colorcpl.exe
  • C:\Windows\SysWOW64\colorcpl.exe

Commands

Copy

Copies the referenced file to C:\Windows\System32\spool\drivers\color\.

Use case: Copies file(s) to a subfolder of a generally trusted folder (c:\Windows\System32), which can be used to hide files or make them blend into the environment.

Privileges: User

colorcpl {PATH}

Detection

Resources