대북 관계자들을 노리는 BlueNorOff(블루노로프)-질문지.doc(2023.04.06)

2023-04-10 • Sakai • BlueNorOff targeting North Korean officials - Questionnaire.doc (2023.04.06) •

https://wezard4u.tistory.com/6412

Thumbnail for 대북 관계자들을 노리는 BlueNorOff(블루노로프)-질문지.doc(2023.04.06)

A Korean malware-analysis post attributes a malicious Word document named Questionnaire.doc to BlueNoroff, described as part of North Korea’s Lazarus-linked cybercrime activity targeting North Korea-related personnel. The lure discusses Kim Ju-ae succession questions and recent North Korean nuclear and missile issues, then asks the user to enable macros. The VBA launches mspaint.exe, allocates memory in that process, writes shellcode, and starts a remote thread before deleting macro modules to hinder analysis. The post lists hashes for the document and reports network indicators including docx1.b4a[.]app/download.html and TCP connections to 3.222.42[.]202:443 and 52.7.66[.]68:443.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3252345b2640efc44cdd98667dbd258… 2023-04-10 2023-05-23
URL https://docx1.b4a.app:443/downl… 2023-04-10 2023-04-10
IPv4 3.222.42.202 2023-04-10 2023-04-10
IPv4 52.7.66.68 2023-04-10 2023-04-10

Related Actors

Related Reports

« Back