대북 관계자들을 노리는 BlueNorOff(블루노로프)-질문지.doc(2023.04.06)

2023-04-10 Sakai BlueNorOff targeting North Korean officials - Questionnaire.doc (2023.04.06)

https://wezard4u.tistory.com/6412

Thumbnail for 대북 관계자들을 노리는 BlueNorOff(블루노로프)-질문지.doc(2023.04.06)

A Korean malware-analysis post attributes a malicious Word document named Questionnaire.doc to BlueNoroff, described as part of North Korea’s Lazarus-linked cybercrime activity targeting North Korea-related personnel. The lure discusses Kim Ju-ae succession questions and recent North Korean nuclear and missile issues, then asks the user to enable macros. The VBA launches mspaint.exe, allocates memory in that process, writes shellcode, and starts a remote thread before deleting macro modules to hinder analysis. The post lists hashes for the document and reports network indicators including docx1.b4a[.]app/download.html and TCP connections to 3.222.42[.]202:443 and 52.7.66[.]68:443.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8f106544bfd4755d17a353064666426a 2023-04-10 2023-05-23
HASH 3252345b2640efc44cdd98667dbd258… 2023-04-10 2023-05-01
HASH 652af768b1bf3f9730737bdd115bbb8… 2023-04-10 2023-04-10
URL https://docx1.b4a.app:443/downl… 2023-04-10 2023-04-10
IPv4 3.222.42.202 2023-04-10 2023-04-10
IPv4 52.7.66.68 2023-04-10 2023-04-10

Related Actors

Related Reports

« Back