Threat Database Backdoors Backdoor.Udr.A

Backdoor.Udr.A

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 9,954
Threat Level: 60 % (Medium)
Infected Computers: 54
First Seen: February 19, 2019
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Backdoor.Udr.A on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise your system's security and allow unauthorized access to your data. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.Udr.A?

Backdoor.Udr.A is a type of malware that creates a secret pathway for hackers to access and control your system remotely. This backdoor can be used to steal sensitive information, install additional malware, or use your system as a botnet to launch attacks on other networks. The presence of Backdoor.Udr.A on your system can lead to serious security breaches and data theft.

How Backdoor.Udr.A Operates

Backdoor.Udr.A operates by exploiting vulnerabilities in your system's security or by tricking you into installing it through social engineering tactics. Once installed, it can create a hidden communication channel with its command and control server, allowing hackers to send commands and receive stolen data. This malware can also disguise itself as a legitimate program or process, making it difficult to detect without proper security tools.

Backdoor.Udr.A can be spread through various means, including infected software downloads, phishing emails, or infected websites. It can also be installed by other malware or viruses that have already compromised your system. Understanding how this malware operates is crucial to preventing future infections and protecting your system from similar threats.

Symptoms of Infection

The symptoms of a Backdoor.Udr.A infection can be subtle, but they may include unusual system behavior, slow performance, or unexplained changes to your system settings. You may also notice unfamiliar programs or processes running in the background, or receive unexpected pop-ups or alerts. In some cases, you may not notice any symptoms at all, which is why regular security scans and monitoring are essential to detecting and removing this type of malware.

  • Unexplained system crashes or freezes
  • Slow system performance or lag
  • Unfamiliar programs or processes running in the background
  • Unexpected pop-ups or alerts
  • Changes to your system settings or configuration

How to Remove Backdoor.Udr.A

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a clean scan.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware or viruses.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed.

Conclusion

Removing Backdoor.Udr.A from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and taking proactive measures to protect your system, you can prevent future infections and keep your data safe. Remember to always use reputable security tools, keep your software up to date, and be cautious when downloading or installing new programs to minimize the risk of malware infections.

Analysis Report

General information

Family Name: Backdoor.Udr.A
Signature status: No Signature

Known Samples

MD5: d8daa873d6d9d0bc191303e871a12e11
SHA1: e11eac3ea3d806ee072279d5f175904fade61d09
SHA256: 319D72307C499935DDB1F4533288E833625ABC0BCB7F20540FAFA48B8034AD05
File Size: 1.08 MB, 1079102 bytes
MD5: 3dfbc7c2dac45728de81a4fbb7ef3d45
SHA1: 7880003c8a06f699abc00715a8388be0300f46ed
SHA256: 0E5633B93DEAE6BCFACB126537431D714A521D5C866D6D0ACFA2A0F49AE4968B
File Size: 1.59 MB, 1586734 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Generic Host Process for Win32 Services
File Version 5.1.2600.0
Internal Name svchost.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename svchost.exe
Product Name Microsoft® Windows® Operating System
Product Version 5.1.2600.0

File Traits

  • 2+ executable sections
  • big overlay
  • upx
  • x86

Block Information

Total Blocks: 379
Potentially Malicious Blocks: 296
Whitelisted Blocks: 83
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x 0 0 0 x x x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x 0 x x x x 0 0 0 x x x 0 x x x x x 0 x x x x x 0 x 0 x x x x 0 x x x x x 0 x x x 0 0 x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 0 x x x x x 0 0 0 0 x x x x 0 0 x 0 x x x x x x 0 x x 0 x x x x x x x 0 x x x 0 0 x x x x x x x x x x 0 0 0 0 x x x x x x x x 0 x x x x x x x 0 x x 0 x x 0 x x x x 0 x x x 0 0 0 x 0 x x x x x 0 x x x x 0 x x x x x 0 0 0 0 x x x 0 0 x 0 x 0 x x x 0 0 x x 0 0 0 x x x x x x x x x 0 x x x 0 0 x x x x x x x 0 x x 0 0 x x x 0 0 0 0 x x x x x x x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Udr.A

Files Modified

File Attributes
c:\windows\spoolsv.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\spoolsv.exe Generic Write,Read Attributes
c:\windows\syswow64\concp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\concp32.exe Generic Write,Read Attributes
c:\windows\syswow64\msiww32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\msiww32.exe Generic Write,Read Attributes
c:\windows\syswow64\mstes32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mstes32.exe Generic Write,Read Attributes
c:\windows\syswow64\vcl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\vcl32.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::sm 렁㗬焄㎽㌤ RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::ax 臲裡╞㠃⬓尃 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::vcl vcl32.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::vcl vcl32.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\active setup\installed components\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::stubpath mstes32.exe RegNtPreCreateKey
HKLM\software\classes\exefile\shell\open\command:: C:\WINDOWS\SysWow64\concp32.exe "%1" %* RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::ax 䬵餾㩋躊럚ﮀᘡ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\active setup\installed components\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::stubpath msiww32.exe RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::u0 虥퉣譯㊭ᝒ悠董噰龓赕ຑ勒巠ᇐ倵ﳷ䴏⾨㫷脆悺ⵌ⍏鼦 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::u1 ᵕخ՘ꝋﵖ頷ꗾ쫿虂띜ꍢ㤖뷚Ɀ䓊⛢ RegNtPreCreateKey
Show More
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::u2 䪥火鈯햬饵껢ࠖ崁䇿ʪᜁ鯼༴꘿딞潝夨諒Ȇ㡰퐉 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::v 165 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup
Network Winsock
  • bind
  • socket

Shell Command Execution

C:\WINDOWS\spoolsv.exe
mprss.exe
lsasm.exe

Related Posts

Trending

Most Viewed

Loading...