Is Seralyth Menu.dll safe?
38 of 75 engines flag this packed unsigned DLL, with seven tier-1 detections converging on Zusy/Kepavll.
Multiple tier-1 engines including Microsoft, Symantec and TrendMicro detect the sample as Zusy/Kepavll. The file is unsigned, packed, and exhibits offensive MITRE techniques T1059.001 and T1620.
37a95bb77001e30a94…3d3297aac45fdaRecommended next actions
Before using
Do not use it. Quarantine this component with your antivirus, then repair or reinstall the parent software from its official source. Do not delete or replace the component manually.
If you already used it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Multiple tier-1 engines including Microsoft, Symantec and TrendMicro detect the sample as Zusy/Kepavll. The file is unsigned, packed, and exhibits offensive MITRE techniques T1059.001 and T1620.
Seven tier-1 engines report the file as malicious with partial family consensus on Zusy. The DLL is unsigned and shows high-entropy code sections consistent with packing. Sandbox execution recorded offensive command-line and process-injection techniques. While two prior imphash matches were previously rated safe, those matches lack signer corroboration and do not outweigh the current tier-1 detections.
What We Detected
38 of 75 engines flagged the sample. Tier-1 detections include Microsoft (Trojan:Win32/Kepavll!rfn), Symantec (Trojan.Zusy!ATN), TrendMicro (Trojan.Win32.KEPAVLL.USBLHQ26), BitDefender, GData, Emsisoft and ESET-NOD32. The file is a 4.1 MB Win32 DLL that is unsigned and contains a high-entropy .text section.
Threat Behavior
One sandbox run observed rundll32 execution of the DLL and recorded MITRE techniques T1059.001 (PowerShell) and T1620 (Reflective Code Loading). no complete contacted-host reputation result was available or dropped children were observed, and external-intel sources returned no hits.
What To Do Now
Do not execute or distribute the file. Keep endpoint protection enabled and scan any systems that may have run the DLL. If the file arrived via email or download, treat the source as compromised.
Where this verdict could be wrong2 caveats
- similarHashes returned two prior safe verdicts on imphash matches (signerCoMatch=false) — framework collision possible, not strong counter-signal.
- contactedHosts is null; no complete host-reputation result available.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- unsigned PE DLL
- high-entropy packed code
- tier-1 engine detections
- offensive MITRE techniques observed
Block the hash and remove the file from any affected systems; maintain current antivirus coverage.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete38 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 15MITRE ATT&CK techniques
- 8spawned processes
- 0network contacts
- 1filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Manipulated how the operating system loads code, which can redirect execution.
High concern: Loaded code directly into memory instead of from a normal file.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Removed execution artefacts or logs, which can conceal activity.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Seralyth Menu.dll
37a95bb77001e30a94bd24dcf36b2bb09db6d3e86882a744dc3d3297aac45fda
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\System32\rundll32.exe" "C:\Users\<USER>\Desktop\readme.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\Seralyth-Menu.dll"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Connect
\Device\ConDrv\\Connect
04Isolated runtime analysis
4 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- \Device\ConDrv\\Connect
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 38 / 75engines flagged
- 279sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
38 of 75 antivirus engines flagged the file, including AhnLab-V3 and ALYac.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 362 times from 279 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: Seralyth Menu.dll — 37a95bb77001e30a94bd24dcf36b2bb09db6d3e86882a744dc3d3297aac45fda
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Windows\System32\rundll32.exe" "C:\Users\<USER>\Desktop\readme.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\Seralyth-Menu.dll"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: Connect — \Device\ConDrv\\Connect
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
PE is packed (high-entropy code or known packer) AND unsigned AND at least one engine flagged it. Packing alone is common in legit software; packing + unsigned + signal is the malware-dropper pattern.
Evidencehigh-entropy code section
38 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
Executable sections have high entropy (7.2+) — the code is compressed or encrypted and only decrypted at runtime. Classic packing behaviour.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Fingerprint and provenance
- File name
- Seralyth Menu.dll
- Format
- Win32 DLL
- Code signing
- No verified publisher
- Size
- 4.0 MB
- Last analyzed
- Sep 3, 2026, 7:40 AM UTC
37a95bb77001e30a94bd24dcf36b2bb09db6d3e86882a744dc3d3297aac45fdaSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't use this component. Quarantine this component with your antivirus, then repair or reinstall the parent software from its official source. Do not delete or replace the component manually.
- Recovery step 02
If you already used it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Reinstall the parent software from the developer's official site instead of replacing this component by itself.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Seralyth Menu.dll malware?
What is Seralyth Menu.dll?
How many antivirus engines detected Seralyth Menu.dll?
I already downloaded and used Seralyth Menu.dll — what should I do?
How do I remove Seralyth Menu.dll?
What kind of malware is Seralyth Menu.dll?
What is the SHA-256 hash of Seralyth Menu.dll?
How up to date is this analysis of Seralyth Menu.dll?
Community
Member reviews and reports for this exact file hash.