Skip to content
View M26Pershing90mm's full-sized avatar
πŸ˜ƒ
πŸ˜ƒ

Block or report M26Pershing90mm

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
M26Pershing90mm/README.md

πŸ”¬ Sakai

Independent cybersecurity blogger and security researcher based in South Korea.

I run κΏˆμ„κΎΈλŠ” νŒŒλž‘μƒˆ (Dreaming Bluebird), a Korean-language blog focused primarily on hands-on analysis of malware, phishing websites, malicious scripts, suspicious files, and related cybersecurity threats.

My goal is not simply to identify something as malicious.

I try to understand:

What does it do?
How does it work?
What techniques does it use?
What indicators does it leave behind?

🌐 Blog: κΏˆμ„κΎΈλŠ” νŒŒλž‘μƒˆ / WEZARD4U'S BLOG


πŸ”¬ Areas of Analysis

My main areas of interest include:

  • 🦠 Malware analysis
  • 🎣 Phishing website analysis
  • πŸ“œ Malicious script analysis
  • πŸ“¦ Suspicious file analysis
  • πŸ•΅οΈ APT and threat research
  • 🌐 Malicious domains and URLs
  • πŸ”Ž Indicators of compromise
  • 🧩 Obfuscation and execution techniques
  • βš™οΈ Persistence and system modification techniques

I mainly focus on the technical analysis of real-world threats and suspicious activity.


🦠 Malware Analysis

I analyze suspicious and malicious files to understand their behavior and technical characteristics.

Depending on the sample, my analysis may include:

  • File hashes
  • File structure
  • Process execution
  • Command-line activity
  • PowerShell
  • VBS
  • JavaScript
  • Registry modification
  • File system changes
  • Persistence mechanisms
  • Network communication
  • Payload behavior
  • Obfuscation techniques

Where useful, I also document indicators such as:

  • MD5
  • SHA-1
  • SHA-256
  • Domains
  • URLs
  • IP addresses
  • File paths
  • Registry paths
  • Mutexes
  • Process names

The objective is to leave enough technical information for others to understand and verify the behavior of the threat.


🎣 Phishing & Malicious Website Analysis

Phishing and malicious website analysis is another major part of my work.

I examine suspicious websites, phishing pages, redirects, and related infrastructure.

Analysis may include:

  • Fake login pages
  • Credential theft pages
  • Smishing-related websites
  • Malicious redirects
  • Suspicious JavaScript
  • Fake software download pages
  • Malicious domains
  • URL structures
  • Hosting infrastructure
  • Related payloads
  • Social-engineering techniques

I try to examine not only what the page looks like, but also what happens behind it.


πŸ•΅οΈ Threat & APT Research

Some malware samples or phishing campaigns may show similarities to previously reported threat groups or APT activity.

In these cases, I try to separate:

  • βœ… Confirmed technical findings
  • πŸ”Ž Similarities with known campaigns
  • ⚠️ Suspected attribution
  • ❓ Unconfirmed assumptions

When the available evidence is insufficient, I prefer terms such as:

  • suspected
  • likely
  • possibly related

rather than presenting attribution as a confirmed fact.


πŸ§ͺ Analysis Approach

Depending on the case, my analysis may involve:

  • πŸ” Static analysis
  • ▢️ Dynamic analysis
  • 🌐 Network traffic observation
  • πŸ“œ Script inspection
  • πŸ“¦ File structure analysis
  • πŸ”— Domain and URL investigation
  • πŸ”Ž Public threat intelligence
  • 🧭 Cross-checking indicators with existing reports

I try to base my conclusions on observable technical evidence whenever possible.

The purpose of my analysis is to understand how threats operate, document useful indicators, and share technical information that may help with defensive security and threat awareness.


🌏 Open-Source Localization

When I have time, I also contribute to the Korean localization of open-source software.

My localization interests mainly include:

  • πŸ” Security software
  • πŸ›‘οΈ Privacy tools
  • 🧰 Utilities
  • πŸ’» Technical software
  • 🌐 Open-source applications

I try to preserve the technical meaning of the original text while making the Korean translation natural and understandable.

Other open-source localization projects may follow as time permits.


β˜• Support My Research

I spend a significant amount of my free time analyzing malware, phishing websites, malicious scripts, suspicious files, and related cybersecurity threats.

Maintaining this work may require:

  • πŸ’Ύ Storage
  • πŸ” Security tools
  • 🧰 Analysis software
  • 🌐 Blog maintenance
  • πŸ“ Technical documentation
  • 🌏 Open-source localization

If my analysis or articles have been useful to you, you can support my work through Ko-fi.

Even a small contribution helps me continue researching, analyzing, documenting, and sharing technical information.

Support my research on Ko-fi

Thank you for supporting my work. πŸ’™


πŸ‡°πŸ‡· ν•œκ΅­μ—μ„œ ν›„μ›ν•˜κΈ°

μ €λŠ” μ•…μ„±μ½”λ“œ, ν”Όμ‹± μ‚¬μ΄νŠΈ, μ•…μ„± 슀크립트, μ˜μ‹¬μŠ€λŸ¬μš΄ 파일 λ“± μ‹€μ œ 사이버 μœ„ν˜‘μ„ 직접 λΆ„μ„ν•˜κ³  κ·Έ κ³Όμ •μ—μ„œ ν™•μΈν•œ λ‚΄μš©μ„ κΏˆμ„κΎΈλŠ” νŒŒλž‘μƒˆ λΈ”λ‘œκ·Έλ₯Ό 톡해 κ³΅μœ ν•˜κ³  μžˆμŠ΅λ‹ˆλ‹€.

λ‹¨μˆœνžˆ μ•…μ„± μ—¬λΆ€λ₯Ό ν™•μΈν•˜λŠ” 것에 κ·ΈμΉ˜μ§€ μ•Šκ³  κ°€λŠ₯ν•œ λ²”μœ„μ—μ„œ λ‹€μŒκ³Ό 같은 λ‚΄μš©μ„ μ‚΄νŽ΄λ³΄κ³  μžˆμŠ΅λ‹ˆλ‹€.

  • 🦠 μ•…μ„±μ½”λ“œ λ™μž‘ 방식
  • 🎣 ν”Όμ‹± μ‚¬μ΄νŠΈ ꡬ쑰
  • πŸ“œ μ•…μ„± 슀크립트
  • 🌐 μ•…μ„± 도메인 및 URL
  • πŸ”Ž μΉ¨ν•΄ μ§€ν‘œ
  • βš™οΈ 지속성 μœ μ§€ 기법
  • 🧩 λ‚œλ…ν™” 및 μ‹€ν–‰ 방식

λ˜ν•œ μ‹œκ°„μ΄ ν—ˆλ½ν•  λ•Œ μ˜€ν”ˆμ†ŒμŠ€ ν”„λ‘œκ·Έλž¨μ˜ ν•œκ΅­μ–΄ λ²ˆμ—­κ³Ό ν˜„μ§€ν™” μž‘μ—…μ—λ„ μ°Έμ—¬ν•˜κ³  μžˆμŠ΅λ‹ˆλ‹€.

제 뢄석 κΈ€μ΄λ‚˜ 기술 μžλ£Œκ°€ 도움이 λ˜μ…¨λ‹€λ©΄ 카카였페이λ₯Ό 톡해 응원해 μ£Όμ‹€ 수 μžˆμŠ΅λ‹ˆλ‹€.

카카였페이 후원 QR μ½”λ“œ
πŸ“± μΉ΄μΉ΄μ˜€ν†‘ μ•±μ—μ„œ QR μ½”λ“œλ₯Ό μŠ€μΊ”ν•˜μ—¬ ν›„μ›ν•˜μ‹€ 수 μžˆμŠ΅λ‹ˆλ‹€.

λ³΄λ‚΄μ£Όμ‹œλŠ” 후원은 λ‹€μŒκ³Ό 같은 ν™œλ™μ— 도움이 λ©λ‹ˆλ‹€.

  • πŸ”¬ λ³΄μ•ˆ 뢄석 및 연ꡬ
  • 🦠 μ•…μ„±μ½”λ“œ 뢄석
  • 🎣 ν”Όμ‹± μ‚¬μ΄νŠΈ 뢄석
  • 🧰 뢄석 도ꡬ ν™œμš©
  • 🌐 λΈ”λ‘œκ·Έ 운영
  • πŸ“ 기술 자료 μž‘μ„±
  • 🌏 μ˜€ν”ˆμ†ŒμŠ€ ν•œκ΅­μ–΄ ν˜„μ§€ν™”

후원 κΈˆμ•‘μ€ μ€‘μš”ν•˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€.

뢄석 글이 도움이 λ˜μ—ˆλ‹€κ³  μƒκ°ν•˜μ‹ λ‹€λ©΄ μ»€ν”Όλ‚˜ 음료 ν•œ μž” μ •λ„μ˜ μž‘μ€ 응원도 μ•žμœΌλ‘œ 뢄석 ν™œλ™μ„ κ³„μ†ν•˜λŠ” 데 도움이 λ©λ‹ˆλ‹€.

후원 여뢀와 관계없이 일반적인 λ³΄μ•ˆ 뢄석 κΈ€κ³Ό 기술 μ •λ³΄λŠ” 계속 κ³΅κ°œν•  μ˜ˆμ •μž…λ‹ˆλ‹€.

κ°μ‚¬ν•©λ‹ˆλ‹€. πŸ’™


⚠️ Security Research Notice

Malware, phishing URLs, malicious scripts, suspicious files, and other potentially harmful materials discussed in my research should be handled only in appropriate controlled environments.

The information published through my blog and GitHub is intended primarily for:

  • πŸ›‘οΈ Defensive cybersecurity research
  • πŸ”¬ Malware analysis
  • 🎣 Phishing analysis
  • πŸŽ“ Education
  • ⚠️ Threat awareness
  • πŸ“ Technical documentation

πŸ”— Links

🌐 Blog
κΏˆμ„κΎΈλŠ” νŒŒλž‘μƒˆ

β˜• Ko-fi
Support My Research

πŸ¦‹ Bluesky
sakaijjang.bsky.social

𝕏 X / Twitter
@sakaijjang

πŸ’» GitHub
@M26Pershing90mm


πŸ”¬ Analyze Β· Understand Β· Document Β· Share

Popular repositories Loading

  1. CanvasBlocker CanvasBlocker Public

    Forked from kkapsner/CanvasBlocker

    A Firefox extension to protect from being fingerprinted.

    JavaScript

  2. pe-bear pe-bear Public

    Forked from hasherezade/pe-bear

    Korean translation and localization work for PE-bear.

    C++

  3. M26Pershing90mm M26Pershing90mm Public template

  4. upscayl upscayl Public

    Forked from upscayl/upscayl

    πŸ†™ Upscayl - #1 Free and Open Source AI Image Upscaler for Linux, MacOS and Windows.

    TypeScript

  5. Sandboxie Sandboxie Public

    Forked from sandboxie-plus/Sandboxie

    Sandboxie Plus & Classic

    C

  6. koodo-reader koodo-reader Public

    Forked from koodo-reader/koodo-reader

    A modern ebook manager and reader with sync and backup capacities for Windows, macOS, Linux, Android, iOS and Web

    JavaScript