Analysis of Phishing Case Impersonating a Famous Korean Portal Login Page
ID: f4b1192d-d767-5e90-b852-01faba01e9f6
STIX ID: report--f4b1192d-d767-5e90-b852-01faba01e9f6
Feed Name: ASEC
Threat Score
AhnLab ASEC analyzed a phishing operation that used a convincingly replicated Korean portal login page to collect user credentials; credentials submitted via POST were processed by PHP on the attacker server, where the code extracted email/password, parsed client OS/browser from the user agent, queried geoPlugin for IP geolocation, and assembled an email containing the stolen data which was sent to multiple attacker-controlled addresses (report includes code snippets and an MD5 indicator).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
