대북 관계자들을 노리는 BlueNorOff(블루노로프)-질문지.doc(2023.04.06)
2023-04-10 • Sakai • BlueNorOff targeting North Korean officials - Questionnaire.doc (2023.04.06) •
A Korean malware-analysis post attributes a malicious Word document named Questionnaire.doc to BlueNoroff, described as part of North Korea’s Lazarus-linked cybercrime activity targeting North Korea-related personnel. The lure discusses Kim Ju-ae succession questions and recent North Korean nuclear and missile issues, then asks the user to enable macros. The VBA launches mspaint.exe, allocates memory in that process, writes shellcode, and starts a remote thread before deleting macro modules to hinder analysis. The post lists hashes for the document and reports network indicators including docx1.b4a[.]app/download.html and TCP connections to 3.222.42[.]202:443 and 52.7.66[.]68:443.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8f106544bfd4755d17a353064666426a | 2023-04-10 | 2023-05-23 |
| HASH | 3252345b2640efc44cdd98667dbd258… | 2023-04-10 | 2023-05-01 |
| HASH | 652af768b1bf3f9730737bdd115bbb8… | 2023-04-10 | 2023-04-10 |
| URL | https://docx1.b4a.app:443/downl… | 2023-04-10 | 2023-04-10 |
| IPv4 | 3.222.42.202 | 2023-04-10 | 2023-04-10 |
| IPv4 | 52.7.66.68 | 2023-04-10 | 2023-04-10 |