Independent cybersecurity blogger and security researcher based in South Korea.
I run κΏμκΎΈλ νλμ / WEZARD4U'S BLOG, a Korean-language personal technical blog focused primarily on hands-on analysis of malware, phishing websites, malicious scripts, suspicious files, and related cybersecurity threats.
The blog is not limited to cybersecurity. I also write about Windows, software, security updates, privacy tools, utilities, open-source software, technical troubleshooting, and other topics that interest me.
My goal is not simply to identify something as malicious.
I try to understand:
What does it do?
How does it work?
What techniques does it use?
What indicators does it leave behind?
π Blog: κΏμκΎΈλ νλμ / WEZARD4U'S BLOG
My main areas of interest include:
- π¦ Malware analysis
- π£ Phishing website analysis
- π Malicious script analysis
- π¦ Suspicious file analysis
- π΅οΈ APT and threat research
- π Malicious domains and URLs
- π Indicators of compromise
- π§© Obfuscation and execution techniques
- βοΈ Persistence and system modification techniques
I mainly focus on the technical analysis of real-world threats and suspicious activity.
Whenever possible, I try to distinguish confirmed technical findings from assumptions, similarities, and attribution claims.
I analyze suspicious and malicious files to understand their behavior and technical characteristics.
Depending on the sample, my analysis may include:
- File hashes
- File structure
- Process execution
- Command-line activity
- PowerShell
- VBS
- JavaScript
- Registry modification
- File system changes
- Persistence mechanisms
- Network communication
- Payload behavior
- Obfuscation techniques
Where useful, I also document indicators such as:
- MD5
- SHA-1
- SHA-256
- Domains
- URLs
- IP addresses
- File paths
- Registry paths
- Mutexes
- Process names
The objective is to leave enough technical information for others to understand and verify the behavior of the threat.
Phishing and malicious website analysis is another major part of my work.
I examine suspicious websites, phishing pages, redirects, scripts, domains, and related infrastructure.
Analysis may include:
- Fake login pages
- Credential theft pages
- Smishing-related websites
- Malicious redirects
- Suspicious JavaScript
- Fake software download pages
- Malicious domains
- URL structures
- Hosting infrastructure
- Related payloads
- Social-engineering techniques
I try to examine not only what the page looks like, but also what happens behind it.
This may include redirects, scripts, network requests, domain relationships, downloaded payloads, and related infrastructure.
Some malware samples or phishing campaigns may show similarities to previously reported threat groups or APT activity.
In these cases, I try to separate:
- β Confirmed technical findings
- π Similarities with known campaigns
β οΈ Suspected attribution- β Unconfirmed assumptions
When the available evidence is insufficient, I prefer terms such as:
- suspected
- likely
- possibly related
- shows similarities to
rather than presenting attribution as a confirmed fact.
Attribution should be based on available technical evidence rather than assumptions.
Depending on the case, my analysis may involve:
- π Static analysis
βΆοΈ Dynamic analysis- π Network traffic observation
- π Script inspection
- π¦ File structure analysis
- π Domain and URL investigation
- π Public threat intelligence
- π§ Cross-checking indicators with existing reports
I try to base my conclusions on observable technical evidence whenever possible.
The purpose of my analysis is to understand how threats operate, document useful indicators, and share technical information that may help with defensive security and threat awareness.
When I have time, I also contribute to the Korean localization of open-source software.
My localization interests mainly include:
- π Security software
- π‘οΈ Privacy tools
- π§° Utilities
- π» Technical software
- π Open-source applications
I try to preserve the technical meaning of the original text while making the Korean translation natural and understandable.
Other open-source localization projects may follow as time permits.
I spend a significant amount of my free time analyzing malware, phishing websites, malicious scripts, suspicious files, and related cybersecurity threats.
Maintaining this work may require:
- πΎ Storage
- π Security tools
- π§° Analysis software
- π₯οΈ Analysis environments
- π Blog maintenance
- π Technical documentation
- π Open-source localization
If my analysis or articles have been useful to you, you can support my work through Ko-fi.
Even a small contribution helps me continue analyzing threats, documenting findings, maintaining my analysis environment, and sharing technical information.
β Ko-fi: https://ko-fi.com/sakai38666
Every coffee helps me analyze the next threat.
For more information about supporting my work:
π Support Independent Malware & Phishing Analysis β WEZARD4U'S BLOG
Support is completely optional.
Regular security analysis, technical articles, and useful information will continue to be shared publicly regardless of support.
μ λ μ μ±μ½λ, νΌμ± μ¬μ΄νΈ, μ μ± μ€ν¬λ¦½νΈ, μμ¬μ€λ¬μ΄ νμΌ λ± μ€μ μ¬μ΄λ² μνμ μ§μ λΆμνκ³ κ·Έ κ³Όμ μμ νμΈν κΈ°μ μ μΈ λ΄μ©μ κΏμκΎΈλ νλμ λΈλ‘κ·Έλ₯Ό ν΅ν΄ 곡μ νκ³ μμ΅λλ€.
λ¨μν μ μ± μ¬λΆλ₯Ό νμΈνλ κ²μ κ·ΈμΉμ§ μκ³ κ°λ₯ν λ²μμμ λ€μκ³Ό κ°μ λ΄μ©μ μ΄ν΄λ³΄κ³ μμ΅λλ€.
- π¦ μ μ±μ½λ λμ λ°©μ
- π£ νΌμ± μ¬μ΄νΈ ꡬ쑰μ λμ
- π μ μ± μ€ν¬λ¦½νΈ
- π¦ μμ¬μ€λ¬μ΄ νμΌ λ° νμ΄λ‘λ
- π μ μ± λλ©μΈ λ° URL
- π μΉ¨ν΄ μ§ν
- βοΈ μ§μμ± μ μ§ κΈ°λ²
- π§© λλ ν λ° μ€ν λ°©μ
- π κ΄λ ¨ λ€νΈμν¬ λ° μν μΈνλΌ
λν μκ°μ΄ νλ½ν λλ μ€νμμ€ νλ‘κ·Έλ¨μ νκ΅μ΄ λ²μκ³Ό νμ§ν μμ μλ μ°Έμ¬νκ³ μμ΅λλ€.
μ λΆμ κΈμ΄λ κΈ°μ μλ£κ° λμμ΄ λμ ¨λ€λ©΄ μΉ΄μΉ΄μ€νμ΄λ₯Ό ν΅ν΄ λΆμ νλμ μμν΄ μ£Όμ€ μ μμ΅λλ€.
π± μΉ΄μΉ΄μ€ν‘ λλ μΉ΄μΉ΄μ€νμ΄μμ QR μ½λλ₯Ό μ€μΊνμ¬ νμνμ€ μ μμ΅λλ€.
보λ΄μ£Όμλ νμμ λ€μκ³Ό κ°μ νλμ λμμ΄ λ©λλ€.
- π¬ 보μ λΆμ λ° μ‘°μ¬
- π¦ μ μ±μ½λ λΆμ
- π£ νΌμ± μ¬μ΄νΈ λΆμ
- π μ μ± μ€ν¬λ¦½νΈ λΆμ
- π§° λΆμ λꡬ λ° μννΈμ¨μ΄
- π₯οΈ λΆμ νκ²½ μ μ§
- πΎ λΆμ μλ£ λ° μ μ₯ 곡κ°
- π λΈλ‘κ·Έ μ΄μ
- π κΈ°μ μλ£ μμ±
- π μ€νμμ€ νκ΅μ΄ νμ§ν
νμ κΈμ‘μ ν¬κΈ°λ μ€μνμ§ μμ΅λλ€.
λΆμ κΈμ΄λ κΈ°μ μλ£κ° λμμ΄ λμλ€κ³ μκ°νμ λ€λ©΄ 컀νΌλ μλ£ ν μ μ λμ μμ μμλ μμΌλ‘ λΆμ νλμ κ³μνλ λ° λμμ΄ λ©λλ€.
μμΈν νμ μλ΄λ λΈλ‘κ·Έμμλ νμΈν μ μμ΅λλ€.
π νμ μλ΄ β κΏμκΎΈλ νλμ
νμ μ¬λΆμ κ΄κ³μμ΄ μΌλ°μ μΈ λ³΄μ λΆμ κΈκ³Ό κΈ°μ μ 보λ κ³μ 곡κ°ν μμ μ λλ€.
κΈμ μ μΈ νμλΏλ§ μλλΌ λΈλ‘κ·Έ κΈμ μ½μ΄μ£Όμκ±°λ νμν μ¬λμκ² κ³΅μ ν΄ μ£Όμλ κ²λ ν° λμμ΄ λ©λλ€.
κ°μ¬ν©λλ€. π
Malware, phishing URLs, malicious scripts, suspicious files, and other potentially harmful materials discussed in my research should be handled only in appropriate controlled environments.
The information published through my blog and GitHub is intended primarily for:
- π‘οΈ Defensive cybersecurity research
- π¬ Malware analysis
- π£ Phishing analysis
- π Education
β οΈ Threat awareness- π Technical documentation
Do not execute suspicious samples or intentionally access malicious infrastructure on production systems.
Use appropriate isolation and security controls when handling potentially harmful material.
π Blog
κΏμκΎΈλ νλμ / WEZARD4U'S BLOG
β Ko-fi
Support My Research
π°π· Support
νμ μλ΄
π¦ Bluesky
sakaijjang.bsky.social
π X / Twitter
@sakaijjang
π» GitHub
@M26Pershing90mm

