Threat Database Backdoors Backdoor.Udr.A

Backdoor.Udr.A

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 12,653
Threat Level: 60 % (Medium)
Infected Computers: 48
First Seen: February 19, 2019
Last Seen: May 22, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Udr.A
Signature status: No Signature

Known Samples

MD5: d8daa873d6d9d0bc191303e871a12e11
SHA1: e11eac3ea3d806ee072279d5f175904fade61d09
SHA256: 319D72307C499935DDB1F4533288E833625ABC0BCB7F20540FAFA48B8034AD05
File Size: 1.08 MB, 1079102 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Generic Host Process for Win32 Services
File Version 5.1.2600.0
Internal Name svchost.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename svchost.exe
Product Name Microsoft® Windows® Operating System
Product Version 5.1.2600.0

File Traits

  • 2+ executable sections
  • big overlay
  • upx
  • x86

Block Information

Total Blocks: 379
Potentially Malicious Blocks: 296
Whitelisted Blocks: 83
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x 0 0 0 x x x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x 0 x x x x 0 0 0 x x x 0 x x x x x 0 x x x x x 0 x 0 x x x x 0 x x x x x 0 x x x 0 0 x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 0 x x x x x 0 0 0 0 x x x x 0 0 x 0 x x x x x x 0 x x 0 x x x x x x x 0 x x x 0 0 x x x x x x x x x x 0 0 0 0 x x x x x x x x 0 x x x x x x x 0 x x 0 x x 0 x x x x 0 x x x 0 0 0 x 0 x x x x x 0 x x x x 0 x x x x x 0 0 0 0 x x x 0 0 x 0 x 0 x x x 0 0 x x 0 0 0 x x x x x x x x x 0 x x x 0 0 x x x x x x x 0 x x 0 0 x x x 0 0 0 0 x x x x x x x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Udr.A

Files Modified

File Attributes
c:\windows\syswow64\concp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\concp32.exe Generic Write,Read Attributes
c:\windows\syswow64\mstes32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\mstes32.exe Generic Write,Read Attributes
c:\windows\syswow64\vcl32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\vcl32.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::sm 렁㗬焄㎽㌤ RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::ax 臲裡╞㠃⬓尃 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::vcl vcl32.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::vcl vcl32.exe RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\active setup\installed components\{be6cf229-8b9a-11d5-eba1-f78eeeeee983}::stubpath mstes32.exe RegNtPreCreateKey
HKLM\software\classes\exefile\shell\open\command:: C:\WINDOWS\SysWow64\concp32.exe "%1" %* RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...