Doesn’t have any English but posted daily: https://ournationschool.podbean.com/
Author: nick
New Page Added
It’s been a long time but I’ve finally added a new page. You can find a link to it in the top menu bar. I’ve been tracking passive DNS requests out of North Korea. It’s not perfect and it doesn’t seem like anything resolves but I wanted to at least get it added as I start to look into it more.
New Red Star Vuln?
I was looking for some vulns in red star the other day and I noticed that I couldn’t log into the VM with the root creds. Not sure if it was something in the scans but working backwards now to see what I can find.
korstamp.com.kp
A new site in North Korea about stamps. Haven’t had too much of a chance to dig into it yet but it’s interesting to see a gmail address at the bottom of the main page.
Configuring Red Star Server
[root@localhost ~]# beam-setup **************************************** 《빛발》관리자의 식별자와 암호를 설정합니다. 관리자의 식별자: admin 관리자암호: 암호확인: **************************************** 《빛발》에 리용할 포구번호를 설정합니다. 포구번호:90 포구번호는 10000이상 65536이하여야 합니다. 포구번호:10000 빛발설정이 완료되였습니다. service beam start 지령으로 《빛발》을 실행할수 있습니다. [root@localhost ~]# rssmon-setup 봉사기감시프로그람은 이미 설정되여있습니다. [root@localhost ~]# beam-setup **************************************** Set the administrator’s identifier and password. Administrator’s identifier: admin Administrator password: Confirm Password: **************************************** Set the muzzle number to be used in 《Lights》. Port number: 90 Port number must be between 10000 and 65536. Port number:10000 Light setting is complete. service beam start You can execute 《Lights》 by command. [root@localhost ~]# rssmon-setup The volunteer watchdog program is already set up.
New Mail Server
Looks like a new mail server is in use here: mail.star-di.net.kp
Another Public Software Finding
Nothing too exciting but found another public site with info about a .sys file from KCC: http://windowfdb.com/d.php?q=nthard-sys-c-windows-system32-drivers
New Domain
Looks like a new domain ftpsek.star.net.kp resolving to 175.45.177.16
New IP Address
I’m not sure when this changed, or if it’s legitimate but it looks like https://ipinfo.io/194.50.111.122 is now showing as located in North Korea.
Seems to be a number of websites reporting the same thing. Whois data from Domain Tools give a little more information. Seems to be used for routing purposes with anycast
% Abuse contact for ‘194.50.111.122 – 194.50.111.122’ is ”
inetnum: 194.50.111.122 – 194.50.111.122
netname: KP-SECUREBIT-20200202
descr: Securebit Anycast Network Democratic People’s Republic of Korea
country: KP
admin-c: SBAC-RIPE
tech-c: SBTC-RIPE
status: ASSIGNED PA
mnt-by: SBMT
created: 2020-02-02T02:03:44Z
last-modified: 2020-02-02T02:03:44Z
source: RIPE
STS Tech Service/Magnolia
STS Tech Service/Magnolia appears to be a North Korean software developer from the early 2000’s that published some software commercially. I’ve been working on tracking down a list of the software and any information that I can find. Will be adding more here as I find it
Rescue File Restoration: http://www.sourcenext.info/sp/press/04027_kyushutsu.html