colorcpl.exe

  • File Path: C:\Windows\SysWOW64\colorcpl.exe
  • Description: Microsoft Color Control Panel

Screenshot

colorcpl.exe

Hashes

Type Hash
MD5 DB71E132EBF1FEB6E93E8A2A0F0C903D
SHA1 7E9B267FAEE4593DF44E41B0A5FB900DE62060FB
SHA256 2E5E0B8FE1C6A6314145E404C46ACC4FF227AD63D0F2765D5458D0C4CB80C110
SHA384 89E250EDBE6666745DA30938A521C0839709A69935C5AAEA76E7B8825C7650CC937E0320E9F717B0B56770F4754CAEA2
SHA512 9F3B00A452B5D528AC27EC0D100A938753A70A300E7EADC40A3E4456C6223FD8D61393D3EE6995F2D6D0ADEC4AE48296B4C04ABB89A28FECF82DEC5B0975583E
SSDEEP 1536:fPbIPfSbS9vMBN7rQOJ7CFToTCzhcRguhwxTyPCb3lZpdym4dy7p:nEXlvq7jSP1cR2prbpdCY9
IMP FE642844D8BB41A0A5162838127D9366
PESHA1 EA38FC2A99AC6B8307C468863F645DD89AD69A1C
PE256 9ED1874F0D6813096B80A3E370308A0068F52C2ED0CC1DFFB919D5769995F50B

Runtime Data

Window Title:

Color Management

Open Handles:

Path Type
(R-D) C:\Windows\Fonts\StaticCache.dat File
(R-D) C:\Windows\System32\en-US\colorcpl.exe.mui File
(R-D) C:\Windows\System32\en-US\colorui.dll.mui File
(R-D) C:\Windows\System32\en-US\duser.dll.mui File
(R-D) C:\Windows\SystemResources\imageres.dll.mun File
(R-D) C:\Windows\WinSxS\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df\comctl32.dll.mui File
(RW-) C:\Users\user File
(RW-) C:\Windows File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_130e63d987a738df File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627 File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\Windows\Theme1175649999 Section
\Windows\Theme601709542 Section

Loaded Modules:

Path
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll
C:\Windows\SysWOW64\colorcpl.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: colorcpl.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/2e5e0b8fe1c6a6314145e404c46acc4ff227ad63d0f2765d5458d0c4cb80c110/detection

File Similarity (ssdeep match)

File Score
C:\windows\system32\colorcpl.exe 96
C:\WINDOWS\system32\colorcpl.exe 96
C:\Windows\system32\colorcpl.exe 96
C:\Windows\system32\colorcpl.exe 97
C:\WINDOWS\system32\colorcpl.exe 94
C:\Windows\system32\colorcpl.exe 97
C:\windows\SysWOW64\colorcpl.exe 96
C:\WINDOWS\SysWOW64\colorcpl.exe 96
C:\Windows\SysWOW64\colorcpl.exe 96
C:\Windows\SysWOW64\colorcpl.exe 96
C:\WINDOWS\SysWOW64\colorcpl.exe 96

Possible Misuse

The following table contains possible examples of colorcpl.exe being misused. While colorcpl.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma file_event_win_susp_colorcpl.yml title: Suspicious Creation with Colorcpl DRL 1.0
sigma file_event_win_susp_colorcpl.yml description: Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\ DRL 1.0
sigma file_event_win_susp_colorcpl.yml Image\|endswith: \colorcpl.exe DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.