Finding Hidden North Korean Websites

Well this turned out to be sort of a bummer. Last night I noticed on Shodan that 175.45.176.21 has a domain futurere.com.kp associated with it. I started doing some digging into it and really the only thing that I could find at first was the associated hostname mail1.futurere.com.kp. That’s not really anything too noteworthy, neither is the fact that future.com.kp redirected to naenara.com.kp.

What was interesting though is that the site pyongyangtimes.com.kp has a separate sites directory that had a number of websites which included Future Re. I put my notes below, they’re broken out into site title, potential URL for the site, and then the actual URL on pyongyangtimes.com.kp

This was all very interesting at 2 in the morning but I took some notes and went to sleep. I woke up the next morning and all of the sites were taken down. All of the sites that I had found the night before were no longer online.

Screen Shot 2019-12-30 at 4.04.50 PM.png

Even pyongyangtimes.com.kp was displaying an error.

Screen Shot 2019-12-30 at 12.09.31 PM.png

Now, most of the sites are available at http://www.naenara.com.kp/main/index/en/first but it’s still interesting to see that they were hosted elsewhere for a short time.

Tracking Computers and Devices in North Korea

Tracking the active torrenting in North Korea reveals some interesting things. Someone really loves Modern Family, but this also reveals more about the devices inside of North Korea based on the drivers they are downloading:

 

Screen Shot 2019-07-20 at 4.53.02 PMScreen Shot 2019-07-20 at 4.54.43 PM

Here’s a list of the most common IP’s that have been torrenting in the last few months:

175.45.177.173
175.45.177.180
175.45.177.184
175.45.177.186

175.45.178.17
175.45.178.19
175.45.178.21
175.45.178.23
175.45.178.25
175.45.178.31
175.45.178.102
175.45.178.115