logo

Analysis of Phishing Case Impersonating a Famous Korean Portal Login Page

ID: f4b1192d-d767-5e90-b852-01faba01e9f6

STIX ID: report--f4b1192d-d767-5e90-b852-01faba01e9f6

Feed Name: ASEC

Threat Score
50/100

Date Published: 2024-02-02

Date Updated: 2026-04-26

Author: ch.lim

...
...

AhnLab ASEC analyzed a phishing operation that used a convincingly replicated Korean portal login page to collect user credentials; credentials submitted via POST were processed by PHP on the attacker server, where the code extracted email/password, parsed client OS/browser from the user agent, queried geoPlugin for IP geolocation, and assembled an email containing the stolen data which was sent to multiple attacker-controlled addresses (report includes code snippets and an MD5 indicator).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.