I’ve been trying to find a GitHub commit that had a commit from North Korea. For some reason I never saved it. But I found something much more interesting here: https://github.com/Alyzana/kwang-myong-addresses/blob/master/sites-en
I have no idea where the data is from but the user has a list of domains on Naenara. Most of them don’t resolve but the one interesting thing I did find when doing some quick research is that apparently rns.edu.kp did resolve last year. To make things much more interesting the only URL that I could reliably find is rns.edu.kp/AntiVirus
This lead down a further search and I found a references to the BangPae-Client from KIM IL SUNG University MATH. I have no idea what this is but I found these hashes:
3e459baf7f73e38c3779b07db58c2821
9b4a54b93351a35b34299a4d9db16afd
eb18354bc621e53fabf5375ef9b42664
decb5dd7c6a3a74d9b89df2d643af0e4
85ba460b6c11da2c01cef6a296073630
If anyone has a copy and wants to share, I would appreciate it. I haven’t been able to find a copy at all. Additional details are below:
Directories found on disk:
- C:\Program Files\BangPae-Client
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BangPae-Client
Generally, the following files are left on disk:
- C:\Program Files\BangPae-Client\audio\2_13.pcm
- C:\Program Files\BangPae-Client\audio\2_14.pcm
- C:\Program Files\BangPae-Client\audio\2_17.pcm
- C:\Program Files\BangPae-Client\audio\2_19.pcm
- C:\Program Files\BangPae-Client\audio\2_24.pcm
- C:\Program Files\BangPae-Client\audio\2_4.pcm
- C:\Program Files\BangPae-Client\audio\2_9.pcm
- C:\Program Files\BangPae-Client\BangPae-Client.exe
- C:\Program Files\BangPae-Client\GPUCache\data_0
- C:\Program Files\BangPae-Client\GPUCache\data_1
- C:\Program Files\BangPae-Client\GPUCache\data_2
- C:\Program Files\BangPae-Client\GPUCache\data_3
- C:\Program Files\BangPae-Client\GPUCache\index
- C:\Program Files\BangPae-Client\help.pdf
- C:\Program Files\BangPae-Client\iconengines\qsvgicon.dll
- C:\Program Files\BangPae-Client\imageformats\qgif.dll
- C:\Program Files\BangPae-Client\imageformats\qico.dll
- C:\Program Files\BangPae-Client\imageformats\qjpeg.dll
- C:\Program Files\BangPae-Client\imageformats\qsvg.dll
- C:\Program Files\BangPae-Client\kpcholim.ttc
- C:\Program Files\BangPae-Client\kpchopom.ttc
- C:\Program Files\BangPae-Client\libcrypto-1_1-x64.dll
- C:\Program Files\BangPae-Client\libgcc_s_seh-1.dll
- C:\Program Files\BangPae-Client\libssl-1_1-x64.dll
- C:\Program Files\BangPae-Client\libstdc++-6.dll
- C:\Program Files\BangPae-Client\libwinpthread-1.dll
- C:\Program Files\BangPae-Client\lua5.1.dll
- C:\Program Files\BangPae-Client\OpenAL32.dll
- C:\Program Files\BangPae-Client\platforms\qdirect2d.dll
- C:\Program Files\BangPae-Client\platforms\qminimal.dll
- C:\Program Files\BangPae-Client\platforms\qoffscreen.dll
- C:\Program Files\BangPae-Client\platforms\qwindows.dll
- C:\Program Files\BangPae-Client\Poster\poster_big-1.dat
- C:\Program Files\BangPae-Client\Poster\poster_big-2.dat
- C:\Program Files\BangPae-Client\Poster\poster_big-3.dat
- C:\Program Files\BangPae-Client\Poster\poster_big-4.dat
- C:\Program Files\BangPae-Client\Poster\poster_big-5.dat
- C:\Program Files\BangPae-Client\Poster\poster_big-6.dat
- C:\Program Files\BangPae-Client\Poster\poster_small-1.dat
- C:\Program Files\BangPae-Client\Poster\poster_small-2.dat
- C:\Program Files\BangPae-Client\Poster\poster_small-3.dat
- C:\Program Files\BangPae-Client\Poster\poster_small-4.dat
- C:\Program Files\BangPae-Client\Poster\poster_small-5.dat
- C:\Program Files\BangPae-Client\Poster\poster_small-6.dat
- C:\Program Files\BangPae-Client\Qt5Core.dll
- C:\Program Files\BangPae-Client\Qt5Gui.dll
- C:\Program Files\BangPae-Client\Qt5Network.dll
- C:\Program Files\BangPae-Client\Qt5Svg.dll
- C:\Program Files\BangPae-Client\Qt5Widgets.dll
- C:\Program Files\BangPae-Client\Qt5Xml.dll
- C:\Program Files\BangPae-Client\RecordSample.sam
- C:\Program Files\BangPae-Client\uninstall.exe
- C:\Program Files\BangPae-Client\Uninstall\IRIMG1.JPG
- C:\Program Files\BangPae-Client\Uninstall\IRIMG2.JPG
- C:\Program Files\BangPae-Client\Uninstall\IRIMG3.JPG
- C:\Program Files\BangPae-Client\Uninstall\uninstall.dat
- C:\Program Files\BangPae-Client\Uninstall\uninstall.xml
- C:\Program Files\BangPae-Client\Win10 Active Tool.exe
- C:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\125\{6D809377-6AF0-444B-8957-A3773F02200E}_BangPae-Client_BangPae-Client_exe
- C:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\125\{6D809377-6AF0-444B-8957-A3773F02200E}_BangPae-Client_help_pdf
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\BangPae-Client.suf.lnk
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\BangPae-Client-1.9.0-20201203.exe.7z.lnk
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\BangPae-Client-1.9.0-20201217.exe.7z.lnk
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\BangPae-Client-1.9.1-20201217.exe.7z.lnk
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BangPae-Client\BangPae-Client.lnk
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BangPae-Client\BangPae-Help.lnk
- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BangPae-Client\Uninstall BangPae-Client.lnk
Use regedit.exe to manually remove from the Windows Registry the keys below:
- HKEY_LOCAL_MACHINE\Software\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\BangPae-Client.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\BangPae-Client1.9.1
Registry values that are not removed from your PC:
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\program files\bangpae-client\bangpae-client.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\program files\bangpae-client\bangpae-client-test-202012282110.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files\BangPae-Client\KCTV.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\D:\dev\meeting system\qTox\Distribution\1.9\Client\BangPae-Client-1.9.1.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\D:\dev\meeting system\qTox\Distribution\1.9\Client\BangPae-Client-1.9.2.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\D:\dev\meeting system\qTox\work\Setup\Client\BangPae-Client-x86_64-release\BangPae-Client.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\D:\dev\meeting system\qTox\work\Setup\Client\BangPae-Client-x86_64-release\BangPae-Client-202013311336.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\J:\Dev\JYJ\New Folder\TEST\BangPae-Client-1.7.7-del.exe.ApplicationCompany
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\J:\Dev\JYJ\New Folder\TEST\BangPae-Client-1.7.7-del.exe.FriendlyAppName
- HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\M:\BangPae-Client.exe.FriendlyAppName
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-1243145971-3851564632-427313449-500\\Device\HarddiskVolume3\Program Files\BangPae-Client\BangPae-Client.exe
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-1243145971-3851564632-427313449-500\\Device\HarddiskVolume3\Program Files\BangPae-Client\uninstall.exe
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\TCP Query User{553D376B-C335-4AEE-AD0A-06DA388B93B0}C:\program files\bangpae-client\bangpae-client.exe
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\TCP Query User{7B36511F-CCE6-433B-99D4-2A8B9AEF8892}C:\program files\bangpae-client\bangpae-client-test-202012282110.exe
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\UDP Query User{1A4B66A6-21CB-441E-83E7-80F6B9F75306}C:\program files\bangpae-client\bangpae-client-test-202012282110.exe
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\UDP Query User{5D3E7543-AF1A-4B21-8EBB-457C0434908C}C:\program files\bangpae-client\bangpae-client.exe