김수키(Kimsuky) 에서 만든 연세대학교 웹메일 피싱 사이트 간단 분석(2024.8.11)
2024-08-12 • Sakai • Brief Analysis of a Yonsei University Webmail Phishing Site Created by Kimsuky (2024.8.11) •
A Kimsuky-attributed phishing analysis examines files for a spoofed Yonsei University webmail page. The source identifies suspected phishing domains and shows PHP logic designed to capture submitted usernames, passwords, request URLs, and client address data. Although the distribution URL was not confirmed, the recovered kit indicates credential-harvesting intent against university webmail users and provides defenders with infrastructure and code patterns for hunting related Kimsuky phishing activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://mail.yonsei.ac.kr/ | 2024-08-07 | 2024-08-12 |
| DOMAIN | wodods.xyz | 2024-08-07 | 2024-08-12 |
Related Actors
Related Reports
Shares tags: Kimsuky, Phishing • Shares 2 IOCs • Published within a week
Shares tags: Kimsuky, Phishing • Same author: Sakai • Published within a month
Shares tags: Kimsuky, Phishing • Same author: Sakai
Shares tags: Kimsuky, Phishing • Same author: Sakai
2024-07-24 •
80% Match
Kimsuky Hackers Create Phishing Site Mimicking Korea University: Are They Targeting Entire Research Institutions?
Criminal IP
Shares tags: Kimsuky, Phishing • Published within a month
Shares tags: Kimsuky, Phishing • Same author: Sakai