김수키 에서 만든 피싱 사이트 고려대학교 지식기반 포털시스템-osihi(.)store/korea(2024.7.21)
2024-07-22 • Sakai • Kimsuky Phishing Site Impersonating Korea University's Knowledge-Based Portal System (2024.7.21) •
Kimsuky is attributed in the excerpt to a credential-phishing page that impersonated Korea University’s knowledge-based portal. The phishing URL hxxp://osihi(.)store/korea/Intro(.)kpd(.)html reused university-themed navigation, sending many menu items to legitimate Korea University services while collecting submitted usernames and passwords through hxxp://osihi(.)store/korea/login(.)php. The author observed victim login data stored under the same /korea/ path on osihi(.)store, indicating that stolen credentials were exposed for download from the phishing infrastructure. The activity matters for defenders because the site was reportedly not broadly blocked by security vendors at the time, making the domain, phishing path, and credential-submission endpoint useful for detection and takedown follow-up.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://osihi.store | 2024-07-22 | 2024-07-22 |
| URL | http://osihi.store/korea/ | 2024-07-22 | 2024-07-22 |
| URL | http://osihi.store/korea/login.… | 2024-07-22 | 2024-07-22 |
| URL | http://osihi.store/korea/Intro.… | 2024-07-22 | 2024-07-22 |
| DOMAIN | osihi.store | 2024-07-22 | 2024-07-22 |