VCDSLoader.exe
Classification: Malicious
VCDSLoader.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 66 antivirus engines.
Detection summary
- 66 antivirus detections
- 4 IDS alerts
- 3 processes observed
- 5 contacted hosts
- 4 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Xred | Triage | 2026-09-02 22:04:51 | 2026-09-02 22:04:51 | malicious-activity | |
| Generic Malware | Hybrid-Analysis | 2024-10-12 10:15:05 | 2026-04-13 19:45:03 |
Tags
evasive xred android backdoor discovery persistenceSample information
- Filenames
- VCDSLoader.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 3451392 bytes
- MD5
dab60710b98e863684efd5bec854cdce- SHA-1
b6244888d6699a528d02c4e8b10cc60d1a40ceae- SHA-256
5bbbb5ba1abe6b620234daa0283e323d14eb738ce34c3b60dc65d9d23bb6bea9- First indexed
- 2024-10-12 09:58:55
- Last updated
- 2026-09-02 22:56:40
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Win32.Comet.A |
| APEX | Malicious |
| AVG | Win32:PUP-gen [PUP] |
| Acronis | suspicious |
| AhnLab-V3 | Win32/Zorex.X1799 |
| Alibaba | Backdoor:Win32/DarkKomet.353 |
| Antiy-AVL | Virus/Win32.DarkKomet.a |
| Arcabit | HEUR.VBA.Trojan.d |
| Avast | Win32:PUP-gen [PUP] |
| Avira | TR/Dldr.Agent.SH |
| BitDefender | Win32.Comet.A |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | W32.Delf.NB4 |
| CTX | exe.trojan.darkkomet |
| ClamAV | Win.Trojan.Emotet-9850453-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Win32.HLLW.Siggen.10555 |
| ESET-NOD32 | Win32/Delf.NBX |
| Elastic | malicious (high confidence) |
| Emsisoft | Win32.Comet.A (B) |
| F-Secure | Malware.W2000M/Dldr.Agent.17651006 |
| FireEye | Generic.mg.dab60710b98e8636 |
| Fortinet | VBA/Agent.IGI!tr.dldr |
| GData | Win32.Backdoor.Agent.AXS |
| Detected | |
| Gridinsoft | Trojan.Win32.Downloader.mz!n |
| Ikarus | Virus.Win32.Delf |
| Jiangmin | Win32/Synaptics.Gen |
| K7AntiVirus | Trojan ( 000112511 ) |
| K7GW | Trojan ( 000112511 ) |
| Kaspersky | Backdoor.Win32.DarkKomet.hqxy |
| Kingsoft | win32.hack.darkkomet.hqxy |
| Lionic | Trojan.Win32.DarkKomet.tp6k |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | W32/Synaptics |
| McAfeeD | ti!5BBBB5BA1ABE |
| MicroWorld-eScan | Win32.Comet.A |
| Microsoft | Worm:Win32/AutoRun!atmn |
| NANO-Antivirus | Trojan.Win32.DarkKomet.fazbwq |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Virus.Synaptics!1.E51C (CLASSIC) |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Synaptics.wc |
| Sophos | Mal/Generic-S |
| Symantec | W32.Zorex |
| Tencent | Virus.Win32.DarkKomet.yb |
| TrendMicro | Virus.Win32.NAPWHICH.B |
| TrendMicro-HouseCall | TROJ_SYMMI_GA250982.UVPM |
| VBA32 | TScope.Trojan.Delf |
| VIPRE | Win32.Comet.A |
| Varist | W32/Backdoor.OAZM-5661 |
| ViRobot | Win32.Zorex.A |
| VirIT | Trojan.Win32.Dnldr22.OHM |
| Webroot | W32.Malware.gen |
| Xcitium | Virus.Win32.Agent.DE@74b38h |
| Yandex | Trojan.GenAsa!ETONJRQzPLk |
| Zillya | Trojan.Delf.Win32.76144 |
| ZoneAlarm | Backdoor.Win32.DarkKomet.hqxy |
| Zoner | Trojan.DOC.132395 |
| alibabacloud | Trojan:Win/Delf.AutoRun |
| huorong | Virus/Synares.a$SA |
Network contacts
142.251.218.110 142.251.46.225 69.42.215.252 142.251.40.238 142.250.72.97
DNS requests
docs.google.com drive.usercontent.google.com freedns.afraid.org xred.mooo.com
Process list
| Name | Command line |
|---|---|
| VCDSLoader.exe | |
| ._cache_VCDSLoader.exe | |
| Synaptics.exe | InjUpdate |