Threat Database Backdoors Backdoor.Udr.A

Backdoor.Udr.A

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 11,635
Threat Level: 60 % (Medium)
Infected Computers: 50
First Seen: February 19, 2019
Last Seen: June 8, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Udr.A
Signature status: No Signature

Known Samples

MD5: d8daa873d6d9d0bc191303e871a12e11
SHA1: e11eac3ea3d806ee072279d5f175904fade61d09
SHA256: 319D72307C499935DDB1F4533288E833625ABC0BCB7F20540FAFA48B8034AD05
File Size: 1.08 MB, 1079102 bytes
MD5: 3dfbc7c2dac45728de81a4fbb7ef3d45
SHA1: 7880003c8a06f699abc00715a8388be0300f46ed
SHA256: 0E5633B93DEAE6BCFACB126537431D714A521D5C866D6D0ACFA2A0F49AE4968B
File Size: 1.59 MB, 1586734 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Generic Host Process for Win32 Services
File Version 5.1.2600.0
Internal Name svchost.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename svchost.exe
Product Name Microsoft® Windows® Operating System
Product Version 5.1.2600.0

File Traits

  • 2+ executable sections
  • big overlay
  • upx
  • x86

Block Information

Total Blocks: 379
Potentially Malicious Blocks: 296
Whitelisted Blocks: 83
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x 0 0 0 x x x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x 0 x x x x 0 0 0 x x x 0 x x x x x 0 x x x x x 0 x 0 x x x x 0 x x x x x 0 x x x 0 0 x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 0 x x x x x 0 0 0 0 x x x x 0 0 x 0 x x x x x x 0 x x 0 x x x x x x x 0 x x x 0 0 x x x x x x x x x x 0 0 0 0 x x x x x x x x 0 x x x x x x x 0 x x 0 x x 0 x x x x 0 x x x 0 0 0 x 0 x x x x x 0 x x x x 0 x x x x x 0 0 0 0 x x x 0 0 x 0 x 0 x x x 0 0 x x 0 0 0 x x x x x x x x x 0 x x x 0 0 x x x x x x x 0 x x 0 0 x x x 0 0 0 0 x x x x x x x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Udr.A

Files Modified

File Attributes
c:\windows\spoolsv.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\spoolsv.exe Generic Write,Read Attributes
c:\windows\syswow64\concp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\concp32.exe Generic Write,Read Attributes
c:\windows\syswow64\msiww32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\msiww32.exe Generic Write,Read Attributes
c:\windows\syswow64\mstes32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mstes32.exe Generic Write,Read Attributes
c:\windows\syswow64\vcl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\vcl32.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::sm 렁㗬焄㎽㌤ RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::ax 臲裡╞㠃⬓尃 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::vcl vcl32.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::vcl vcl32.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\active setup\installed components\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::stubpath mstes32.exe RegNtPreCreateKey
HKLM\software\classes\exefile\shell\open\command:: C:\WINDOWS\SysWow64\concp32.exe "%1" %* RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::ax 䬵餾㩋躊럚ﮀᘡ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\active setup\installed components\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::stubpath msiww32.exe RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::u0 虥퉣譯㊭ᝒ悠董噰龓赕ຑ勒巠ᇐ倵ﳷ䴏⾨㫷脆悺ⵌ⍏鼦 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::u1 ᵕخ՘ꝋﵖ頷ꗾ쫿虂띜ꍢ㤖뷚Ɀ䓊⛢ RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::u2 䪥火鈯햬饵껢ࠖ崁䇿ʪᜁ鯼༴꘿딞潝夨諒Ȇ㡰퐉 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::v 165 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup
Network Winsock
  • bind
  • socket

Shell Command Execution

C:\WINDOWS\spoolsv.exe
mprss.exe
lsasm.exe

Trending

Most Viewed

Loading...