Independent cybersecurity blogger and security researcher based in South Korea.
I run κΏμκΎΈλ νλμ (Dreaming Bluebird), a Korean-language blog focused primarily on hands-on analysis of malware, phishing websites, malicious scripts, suspicious files, and related cybersecurity threats.
My goal is not simply to identify something as malicious.
I try to understand:
What does it do?
How does it work?
What techniques does it use?
What indicators does it leave behind?
π Blog: κΏμκΎΈλ νλμ / WEZARD4U'S BLOG
My main areas of interest include:
- π¦ Malware analysis
- π£ Phishing website analysis
- π Malicious script analysis
- π¦ Suspicious file analysis
- π΅οΈ APT and threat research
- π Malicious domains and URLs
- π Indicators of compromise
- π§© Obfuscation and execution techniques
- βοΈ Persistence and system modification techniques
I mainly focus on the technical analysis of real-world threats and suspicious activity.
I analyze suspicious and malicious files to understand their behavior and technical characteristics.
Depending on the sample, my analysis may include:
- File hashes
- File structure
- Process execution
- Command-line activity
- PowerShell
- VBS
- JavaScript
- Registry modification
- File system changes
- Persistence mechanisms
- Network communication
- Payload behavior
- Obfuscation techniques
Where useful, I also document indicators such as:
- MD5
- SHA-1
- SHA-256
- Domains
- URLs
- IP addresses
- File paths
- Registry paths
- Mutexes
- Process names
The objective is to leave enough technical information for others to understand and verify the behavior of the threat.
Phishing and malicious website analysis is another major part of my work.
I examine suspicious websites, phishing pages, redirects, and related infrastructure.
Analysis may include:
- Fake login pages
- Credential theft pages
- Smishing-related websites
- Malicious redirects
- Suspicious JavaScript
- Fake software download pages
- Malicious domains
- URL structures
- Hosting infrastructure
- Related payloads
- Social-engineering techniques
I try to examine not only what the page looks like, but also what happens behind it.
Some malware samples or phishing campaigns may show similarities to previously reported threat groups or APT activity.
In these cases, I try to separate:
- β Confirmed technical findings
- π Similarities with known campaigns
β οΈ Suspected attribution- β Unconfirmed assumptions
When the available evidence is insufficient, I prefer terms such as:
- suspected
- likely
- possibly related
rather than presenting attribution as a confirmed fact.
Depending on the case, my analysis may involve:
- π Static analysis
βΆοΈ Dynamic analysis- π Network traffic observation
- π Script inspection
- π¦ File structure analysis
- π Domain and URL investigation
- π Public threat intelligence
- π§ Cross-checking indicators with existing reports
I try to base my conclusions on observable technical evidence whenever possible.
The purpose of my analysis is to understand how threats operate, document useful indicators, and share technical information that may help with defensive security and threat awareness.
When I have time, I also contribute to the Korean localization of open-source software.
My localization interests mainly include:
- π Security software
- π‘οΈ Privacy tools
- π§° Utilities
- π» Technical software
- π Open-source applications
I try to preserve the technical meaning of the original text while making the Korean translation natural and understandable.
Other open-source localization projects may follow as time permits.
I spend a significant amount of my free time analyzing malware, phishing websites, malicious scripts, suspicious files, and related cybersecurity threats.
Maintaining this work may require:
- πΎ Storage
- π Security tools
- π§° Analysis software
- π Blog maintenance
- π Technical documentation
- π Open-source localization
If my analysis or articles have been useful to you, you can support my work through Ko-fi.
Even a small contribution helps me continue researching, analyzing, documenting, and sharing technical information.
Thank you for supporting my work. π
μ λ μ μ±μ½λ, νΌμ± μ¬μ΄νΈ, μ μ± μ€ν¬λ¦½νΈ, μμ¬μ€λ¬μ΄ νμΌ λ± μ€μ μ¬μ΄λ² μνμ μ§μ λΆμνκ³ κ·Έ κ³Όμ μμ νμΈν λ΄μ©μ κΏμκΎΈλ νλμ λΈλ‘κ·Έλ₯Ό ν΅ν΄ 곡μ νκ³ μμ΅λλ€.
λ¨μν μ μ± μ¬λΆλ₯Ό νμΈνλ κ²μ κ·ΈμΉμ§ μκ³ κ°λ₯ν λ²μμμ λ€μκ³Ό κ°μ λ΄μ©μ μ΄ν΄λ³΄κ³ μμ΅λλ€.
- π¦ μ μ±μ½λ λμ λ°©μ
- π£ νΌμ± μ¬μ΄νΈ ꡬ쑰
- π μ μ± μ€ν¬λ¦½νΈ
- π μ μ± λλ©μΈ λ° URL
- π μΉ¨ν΄ μ§ν
- βοΈ μ§μμ± μ μ§ κΈ°λ²
- π§© λλ ν λ° μ€ν λ°©μ
λν μκ°μ΄ νλ½ν λ μ€νμμ€ νλ‘κ·Έλ¨μ νκ΅μ΄ λ²μκ³Ό νμ§ν μμ μλ μ°Έμ¬νκ³ μμ΅λλ€.
μ λΆμ κΈμ΄λ κΈ°μ μλ£κ° λμμ΄ λμ ¨λ€λ©΄ μΉ΄μΉ΄μ€νμ΄λ₯Ό ν΅ν΄ μμν΄ μ£Όμ€ μ μμ΅λλ€.
π± μΉ΄μΉ΄μ€ν‘ μ±μμ QR μ½λλ₯Ό μ€μΊνμ¬ νμνμ€ μ μμ΅λλ€.
보λ΄μ£Όμλ νμμ λ€μκ³Ό κ°μ νλμ λμμ΄ λ©λλ€.
- π¬ 보μ λΆμ λ° μ°κ΅¬
- π¦ μ μ±μ½λ λΆμ
- π£ νΌμ± μ¬μ΄νΈ λΆμ
- π§° λΆμ λꡬ νμ©
- π λΈλ‘κ·Έ μ΄μ
- π κΈ°μ μλ£ μμ±
- π μ€νμμ€ νκ΅μ΄ νμ§ν
νμ κΈμ‘μ μ€μνμ§ μμ΅λλ€.
λΆμ κΈμ΄ λμμ΄ λμλ€κ³ μκ°νμ λ€λ©΄ 컀νΌλ μλ£ ν μ μ λμ μμ μμλ μμΌλ‘ λΆμ νλμ κ³μνλ λ° λμμ΄ λ©λλ€.
νμ μ¬λΆμ κ΄κ³μμ΄ μΌλ°μ μΈ λ³΄μ λΆμ κΈκ³Ό κΈ°μ μ 보λ κ³μ 곡κ°ν μμ μ λλ€.
κ°μ¬ν©λλ€. π
Malware, phishing URLs, malicious scripts, suspicious files, and other potentially harmful materials discussed in my research should be handled only in appropriate controlled environments.
The information published through my blog and GitHub is intended primarily for:
- π‘οΈ Defensive cybersecurity research
- π¬ Malware analysis
- π£ Phishing analysis
- π Education
β οΈ Threat awareness- π Technical documentation
π Blog
κΏμκΎΈλ νλμ
β Ko-fi
Support My Research
π¦ Bluesky
sakaijjang.bsky.social
π X / Twitter
@sakaijjang
π» GitHub
@M26Pershing90mm