VCDSLoader.exe

Classification: Malicious

VCDSLoader.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 66 antivirus engines.

Detection summary

  • 66 antivirus detections
  • 4 IDS alerts
  • 3 processes observed
  • 5 contacted hosts
  • 4 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Xred Triage 2026-09-02 22:04:51 2026-09-02 22:04:51 malicious-activity
Generic Malware Hybrid-Analysis 2024-10-12 10:15:05 2026-04-13 19:45:03

Tags

evasive xred android backdoor discovery persistence

Sample information

Filenames
VCDSLoader.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
3451392 bytes
MD5
dab60710b98e863684efd5bec854cdce
SHA-1
b6244888d6699a528d02c4e8b10cc60d1a40ceae
SHA-256
5bbbb5ba1abe6b620234daa0283e323d14eb738ce34c3b60dc65d9d23bb6bea9
First indexed
2024-10-12 09:58:55
Last updated
2026-09-02 22:56:40

Antivirus detections

EngineDetection
ALYacWin32.Comet.A
APEXMalicious
AVGWin32:PUP-gen [PUP]
Acronissuspicious
AhnLab-V3Win32/Zorex.X1799
AlibabaBackdoor:Win32/DarkKomet.353
Antiy-AVLVirus/Win32.DarkKomet.a
ArcabitHEUR.VBA.Trojan.d
AvastWin32:PUP-gen [PUP]
AviraTR/Dldr.Agent.SH
BitDefenderWin32.Comet.A
BkavW32.AIDetectMalware
CAT-QuickHealW32.Delf.NB4
CTXexe.trojan.darkkomet
ClamAVWin.Trojan.Emotet-9850453-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
DrWebWin32.HLLW.Siggen.10555
ESET-NOD32Win32/Delf.NBX
Elasticmalicious (high confidence)
EmsisoftWin32.Comet.A (B)
F-SecureMalware.W2000M/Dldr.Agent.17651006
FireEyeGeneric.mg.dab60710b98e8636
FortinetVBA/Agent.IGI!tr.dldr
GDataWin32.Backdoor.Agent.AXS
GoogleDetected
GridinsoftTrojan.Win32.Downloader.mz!n
IkarusVirus.Win32.Delf
JiangminWin32/Synaptics.Gen
K7AntiVirusTrojan ( 000112511 )
K7GWTrojan ( 000112511 )
KasperskyBackdoor.Win32.DarkKomet.hqxy
Kingsoftwin32.hack.darkkomet.hqxy
LionicTrojan.Win32.DarkKomet.tp6k
MalwarebytesGeneric.Malware.AI.DDS
MaxSecureTrojan.Malware.300983.susgen
McAfeeW32/Synaptics
McAfeeDti!5BBBB5BA1ABE
MicroWorld-eScanWin32.Comet.A
MicrosoftWorm:Win32/AutoRun!atmn
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
Paloaltogeneric.ml
PandaTrj/CI.A
RisingVirus.Synaptics!1.E51C (CLASSIC)
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Synaptics.wc
SophosMal/Generic-S
SymantecW32.Zorex
TencentVirus.Win32.DarkKomet.yb
TrendMicroVirus.Win32.NAPWHICH.B
TrendMicro-HouseCallTROJ_SYMMI_GA250982.UVPM
VBA32TScope.Trojan.Delf
VIPREWin32.Comet.A
VaristW32/Backdoor.OAZM-5661
ViRobotWin32.Zorex.A
VirITTrojan.Win32.Dnldr22.OHM
WebrootW32.Malware.gen
XcitiumVirus.Win32.Agent.DE@74b38h
YandexTrojan.GenAsa!ETONJRQzPLk
ZillyaTrojan.Delf.Win32.76144
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
ZonerTrojan.DOC.132395
alibabacloudTrojan:Win/Delf.AutoRun
huorongVirus/Synares.a$SA

Network contacts

142.251.218.110 142.251.46.225 69.42.215.252 142.251.40.238 142.250.72.97

DNS requests

docs.google.com drive.usercontent.google.com freedns.afraid.org xred.mooo.com

Process list

NameCommand line
VCDSLoader.exe
._cache_VCDSLoader.exe
Synaptics.exeInjUpdate