김수키 에서 만든 피싱 사이트 고려대학교 지식기반 포털시스템-osihi(.)store/korea(2024.7.21)

2024-07-22 Sakai Kimsuky Phishing Site Impersonating Korea University's Knowledge-Based Portal System (2024.7.21)

http://wezard4u.tistory.com/429236

Thumbnail for 김수키 에서 만든 피싱 사이트 고려대학교 지식기반 포털시스템-osihi(.)store/korea(2024.7.21)

Kimsuky is attributed in the excerpt to a credential-phishing page that impersonated Korea University’s knowledge-based portal. The phishing URL hxxp://osihi(.)store/korea/Intro(.)kpd(.)html reused university-themed navigation, sending many menu items to legitimate Korea University services while collecting submitted usernames and passwords through hxxp://osihi(.)store/korea/login(.)php. The author observed victim login data stored under the same /korea/ path on osihi(.)store, indicating that stolen credentials were exposed for download from the phishing infrastructure. The activity matters for defenders because the site was reportedly not broadly blocked by security vendors at the time, making the domain, phishing path, and credential-submission endpoint useful for detection and takedown follow-up.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://osihi.store 2024-07-22 2024-07-22
URL http://osihi.store/korea/ 2024-07-22 2024-07-22
URL http://osihi.store/korea/login.… 2024-07-22 2024-07-22
URL http://osihi.store/korea/Intro.… 2024-07-22 2024-07-22
DOMAIN osihi.store 2024-07-22 2024-07-22

Related Actors

Related Reports

« Back