FILEMembers
FILE

Image-named DLL path set as Remote Desktop service load target

A file dropped as `mediasrv.png` was identified by its hash as a Windows DLL, while separate sandbox reports recorded its path in the Remote Desktop service DLL setting. PowerShell and registry observations support an attempted service reconfiguration, but do not show that the DLL loaded or remote access worked.

Oct 10, 2026, 23:23 (UTC+9)Last seenOct 10, 2026Severity100ByCTX TeamActorTA505Hive0065IOC23

Windows Remote Desktop’s service configuration was pointed at a file named C:\Windows\branding\mediasrv.png. The extension suggests an image, but a separate sandbox report identified a file dropped at that exact path as a 64-bit Windows DLL. Why was an image-named file being selected as a service component? The records reviewed by CTX Threat Intelligence support a concrete answer: the executable under analysis attempted to reconfigure Remote Desktop-related services, including their load target…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence