control.exe
- File Path:
C:\WINDOWS\system32\control.exe
- Description: Windows Control Panel
Hashes
Type | Hash |
---|---|
MD5 | 62D970D8B60F75C12D21C740F2D8A5DA |
SHA1 | D054A1D1E0BECCA5EEF751CF616ECB811CFABECE |
SHA256 | D6E21DA3BE0701162A36F8C9F94E616B1A0C5FD4CC1B52EFD81959CB257957C1 |
SHA384 | 8A51959B1236046F187D89A86FC5595B0C4A7756448F90ED264EB19C7F59D5B2A77D188099F0ACCC4E88CC93CABAAC14 |
SHA512 | AF57DC8A972FB2E0DDB589ABA26AC122CBE2A2CE034102148A24FDCC529E58CA628710160B0FE60BA01740ACF6E591DC74FC094242AD4E82BC8A3F1373DF6569 |
SSDEEP | 1536:zrlJKByp4Ytve/qzSpZ3r1q6QkjfkQUk8+k6kawM1x8Dkf8dani25imK:zK0+Av7Sp5+1k12b/Af885RK |
Signature
- Status: Signature verified.
- Serial:
330000023241FB59996DCC4DFF000000000232
- Thumbprint:
FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: CONTROL.EXE
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.18362.1 (WinBuild.160101.0800)
- Product Version: 10.0.18362.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
File Similarity (ssdeep match)
Possible Misuse
The following table contains possible examples of control.exe
being misused. While control.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | proc_creation_win_susp_control_cve_2021_40444.yml | Image\|endswith: '\control.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_control_cve_2021_40444.yml | - '\control.exe input.dll' |
DRL 1.0 |
sigma | proc_creation_win_susp_control_cve_2021_40444.yml | - '\control.exe" input.dll' |
DRL 1.0 |
sigma | proc_creation_win_susp_control_dll_load.yml | description: Detects suspicious Rundll32 execution from control.exe as used by Equation Group and Exploit Kits |
DRL 1.0 |
sigma | proc_creation_win_susp_control_dll_load.yml | ParentImage\|endswith: '\System32\control.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_workfolders.yml | description: Detects using WorkFolders.exe to execute an arbitrary control.exe |
DRL 1.0 |
sigma | proc_creation_win_susp_workfolders.yml | Image\|endswith: '\control.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_workfolders.yml | Image: 'C:\Windows\System32\control.exe' |
DRL 1.0 |
LOLBAS | Control.yml | Name: Control.exe |
|
LOLBAS | Control.yml | - Command: control.exe c:\windows\tasks\file.txt:evil.dll |
|
LOLBAS | Control.yml | - Path: C:\Windows\System32\control.exe |
|
LOLBAS | Control.yml | - Path: C:\Windows\SysWOW64\control.exe |
|
LOLBAS | Control.yml | - IOC: Control.exe executing files from alternate data streams |
|
LOLBAS | Control.yml | - IOC: Control.exe executing library file without cpl extension |
|
LOLBAS | Control.yml | - IOC: Suspicious network connections from control.exe |
|
LOLBAS | WorkFolders.yml | Description: Execute control.exe in the current working directory |
|
atomic-red-team | T1218.002.md | <blockquote>Adversaries may abuse control.exe to proxy execution of malicious payloads. The Windows Control Panel process binary (control.exe) handles execution of Control Panel items, which are utilities that allow users to view and adjust computer settings. | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.002.md | This test simulates an adversary leveraging control.exe | MIT License. © 2018 Red Canary |
atomic-red-team | T1218.002.md | control.exe #{cpl_file_path} | MIT License. © 2018 Red Canary |
MIT License. Copyright (c) 2020-2021 Strontic.