
Image-named DLL path set as Remote Desktop service load target
A file dropped as `mediasrv.png` was identified by its hash as a Windows DLL, while separate sandbox reports recorded its path in the Remote Desktop service DLL setting. PowerShell and registry observations support an attempted service reconfiguration, but do not show that the DLL loaded or remote access worked.
Windows Remote Desktop’s service configuration was pointed at a file named C:\Windows\branding\mediasrv.png. The extension suggests an image, but a separate sandbox report identified a file dropped at that exact path as a 64-bit Windows DLL. Why was an image-named file being selected as a service component? The records reviewed by CTX Threat Intelligence support a concrete answer: the executable under analysis attempted to reconfigure Remote Desktop-related services, including their load target…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read