{"id":62740,"date":"2025-11-26T13:34:08","date_gmt":"2025-11-26T21:34:08","guid":{"rendered":"https:\/\/www.sumologic.com\/blog\/sha1-hulud-%ed%83%90%ec%a7%80-%eb%a1%9c%ea%b7%b8%eb%8a%94-%eb%b0%98%eb%93%9c%ec%8b%9c-%ed%9d%90%eb%a5%b4%ea%b2%8c-%ed%95%b4%ec%95%bc-%ed%95%9c%eb%8b%a4"},"modified":"2026-01-23T07:03:36","modified_gmt":"2026-01-23T15:03:36","slug":"detect-sha1-hulud","status":"publish","type":"blog","link":"https:\/\/www.sumologic.com\/ko\/blog\/detect-sha1-hulud","title":{"rendered":"SHA1-Hulud \ud0d0\uc9c0: \ub85c\uadf8\ub294 \ud758\ub7ec\uc57c \ud55c\ub2e4"},"content":{"rendered":"\n<section class=\"e-stn e-stn-0d652506f82b000a392973813b918ee25d5b4211 e-stn--glossary-inner-content e-stn--table-of-content\"><div class=\"container\">\n<div class=\"wp-block-b3rg-row e-row row\">\n<div class=\"wp-block-b3rg-column e-col e-col-1f7b3997080fc292474d26ff00c905d99d3520fa e-col--content-wrapper  col-sm-12 col-lg-12 col-xl-12\">\n<div class=\"e-div e-div-a1b32f66e1749758df41d5aea14f647cd10e362c e-div--card-btn-link\">\n<div class=\"wp-block-b3rg-column e-col e-col-ac00a9d18d9973e605ded8ae7af253f1808cf699  col-xs-10 col-sm-9 col-md-6\">\n<figure class=\"wp-block-image size-full w-50 mb-4\"><img loading=\"lazy\" decoding=\"async\" width=\"765\" height=\"291\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/log_threat_labs.png\" alt=\"\" class=\"wp-image-5388\" title=\"\"><\/figure>\n<\/div>\n\n\n\n<p>Sha1-Hulud \uc6dc\uc774 \ub2e4\uc2dc \uc6b0\ub9ac \uc0b6 \uc18d\uc73c\ub85c \ud30c\uace0\ub4e4\uc5c8\uc73c\uba70, \ube60\ub974\uac8c \ud655\uc0b0\ub418\uc5b4 \uadf8 \uc5b4\ub290 \ub54c\ubcf4\ub2e4 \ud070 \ud53c\ud574\ub97c \uc785\ud788\uace0 \uc788\uc2b5\ub2c8\ub2e4. \ub4c4(Dune) \uc2dc\ub9ac\uc988\uc758 \uc720\uba85\ud55c \ubc8c\ub808\uc5d0\uc11c \uc774\ub984\uc744 \ub530\uc628 \uc774 \uacf5\uaca9\uc740 \uc804 \uc138\uacc4 \uc5ec\ub7ec \uc870\uc9c1\uc5d0\ub3c4 \uc601\ud5a5\uc744 \ubbf8\uce58\uace0 \uc788\uc2b5\ub2c8\ub2e4. 2025\ub144 9\uc6d4 16\uc77c \ub300\uaddc\ubaa8 \ud655\uc0b0\uc774 \ucc98\uc74c \ubcf4\uace0\ub41c \uc774\ud6c4, \uc774 \uc6dc\uc740 \ub2e4\uc74c\uacfc \uac19\uc740 \uae30\ubc95\uc744 \uc0ac\uc6a9\ud574 \ub192\uc740 \ud30c\uae09\ub825\uc73c\ub85c \ube60\ub974\uac8c \uc804\ud30c\ub420 \uc218 \uc788\uc74c\uc744 \ubcf4\uc5ec \uc8fc\uace0 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>npm \ud328\ud0a4\uc9c0 \uac1c\ubc1c\uc790\uc758 GitHub \uc790\uaca9 \uc99d\uba85\uc774 \ud0c8\ucde8\ub41c \uac83\uc744 \uc545\uc6a9\ud558\uc5ec \ub110\ub9ac \uc0ac\uc6a9\ub418\ub294 npm \ud328\ud0a4\uc9c0\ub97c \uc545\uc131 \ucf54\ub4dc\ud654\ud569\ub2c8\ub2e4. \ud604\uc7ac <a href=\"https:\/\/github.com\/wiz-sec-public\/wiz-research-iocs\/blob\/main\/reports\/shai-hulud-2-packages.csv\" target=\"_blank\" rel=\"noopener\">\uc57d 800\uac1c\uc758 \uac10\uc5fc\ub41c \ud328\ud0a4\uc9c0\uac00 \ubcf4\uace0\ub418\uc5c8\uc73c\uba70<\/a>, \uc774\ub4e4 \uc911 \uc0c1\ub2f9\uc218\uac00 \ub110\ub9ac \uc0ac\uc6a9\ub418\uace0 \uc788\uc2b5\ub2c8\ub2e4.<\/li>\n\n\n\n<li>\uac10\uc5fc\ub41c npm \ud328\ud0a4\uc9c0\uac00 \ub2e4\uc6b4\ub85c\ub4dc \ubc0f \uc124\uce58\ub418\uba74 GitHub, NPM \ud328\ud0a4\uc9c0 \ub9ac\ud3ec\uc9c0\ud130\ub9ac, AWS \ubc0f Azure \uac19\uc740 \ud074\ub77c\uc6b0\ub4dc \uc81c\uacf5\uc5c5\uccb4\uc758 \uc790\uaca9 \uc99d\uba85\uc744 \uc218\uc9d1\ud569\ub2c8\ub2e4.<\/li>\n\n\n\n<li>\uc218\uc9d1\ub41c \uc790\uaca9 \uc99d\uba85\uc740 \uacf5\uac1c GitHub \ub9ac\ud3ec\uc9c0\ud130\ub9ac\uc5d0 \uac8c\uc2dc\ub429\ub2c8\ub2e4. \uc774 \uae00\uc744 \uc4f0\ub294 \ud604\uc7ac <a href=\"https:\/\/www.linkedin.com\/pulse\/sha1-hulud-supply-chain-nightmare-shook-npm-ecosystem-again-gvnuc\/\" target=\"_blank\" rel=\"noopener\">25,000\uac1c \uc774\uc0c1\uc758 \ub9ac\ud3ec\uc9c0\ud130\ub9ac\uac00 \uc0dd\uc131\ub418\uc5c8\uc2b5\ub2c8\ub2e4<\/a>.<\/li>\n\n\n\n<li>\uc218\uc9d1\ub41c \uc790\uaca9 \uc99d\uba85\uc744 \ud65c\uc6a9\ud574 \ub354 \ub9ce\uc740 NPM \ud328\ud0a4\uc9c0\ub97c \ucd94\uac00\ub85c \uce68\ud574\ud569\ub2c8\ub2e4.<\/li>\n<\/ul>\n\n\n\n<p>\uc774\ubc88 \ubcc0\uc885\uc5d0\ub294 \ub2e4\uc74c\uacfc \uac19\uc740 \uc0c8\ub85c\uc6b4 \ud589\ub3d9\ub3c4 \ud3ec\ucc29\ub418\uc5c8\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\uc720\uc6a9\ud55c \uc790\uaca9 \uc99d\uba85\uc744 \ucde8\ub4dd\ud558\uc9c0 \ubabb\ud55c \uacbd\uc6b0, \ud574\ub2f9 \uba38\uc2e0\uc758 \uc0ac\uc6a9\uc790 \ud648 \ub514\ub809\ud130\ub9ac \ub370\uc774\ud130 \uc0ad\uc81c<\/li>\n\n\n\n<li>\uc190\uc0c1\ub41c \ud638\uc2a4\ud2b8\uc5d0\uc11c C2 \uba85\ub839\uc744 \uc2e4\ud589\ud558\uae30 \uc704\ud574 GitHub \ub9ac\ud3ec\uc9c0\ud130\ub9ac\uc758 \ud1a0\ub860(Discussions)\uc744 \ud65c\uc6a9\ud558\uace0, \ucf54\ub4dc \uc2e4\ud589\uc5d0\ub294 \uc790\uccb4 \ud638\uc2a4\ud305\ub41c GitHub Actions \ub7ec\ub108\ub97c \uc0ac\uc6a9\ud568.<\/li>\n\n\n\n<li>\ud0c8\ucde8\ub41c \uc790\uaca9 \uc99d\uba85\uc744 \ud3ec\ud568\ud558\ub294 git \ub9ac\ud3ec\uc9c0\ud130\ub9ac\uc5d0 \uc0c8\ub85c\uc6b4 \uc774\ub984 \uaddc\uce59\uc744 \uc801\uc6a9\ud568: \uc608\ub97c \ub4e4\uc5b4 &#8216;aoy7angy5kwcq64fb7&#8217;\uacfc \uac19\uc740 \ubb34\uc791\uc704 \ubb38\uc790\uc5f4\uc744 \uc774\ub984\uc73c\ub85c \uc0ac\uc6a9\ud558\uace0, &#8216;Sha1-Hulud: The Second Coming&#8217;\uacfc \uac19\uc740 \ub2e4\uc591\ud55c \uc124\uba85\uc744 \ud3ec\ud568\ud568.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading mt-4\" id=\"detection-opportunities-and-required-logs\">\ud0d0\uc9c0 \uae30\ud68c \ubc0f \ud544\uc694\ud55c \ub85c\uadf8<\/h2>\n\n\n\n<p>\uc801\uc808\ud55c \uc9c0\uc810\uc5d0\uc11c \ub85c\uadf8\ub97c \uc218\uc9d1\ud558\uace0 \uc788\ub2e4\uba74 SHA1-Hulud\ub97c \ud0d0\uc9c0\ud560 \uc218 \uc788\ub294 \uae30\ud68c\ub294 \ub2e4\uc591\ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"github\">GitHub<\/h3>\n\n\n\n<p>GitHub Enterprise \uac10\uc0ac(Audit) \ub85c\uae45\uc740 \ud544\uc218\uc785\ub2c8\ub2e4. \ud0d0\uc9c0 \uae30\ud68c\uc5d0\ub294 \ub2e4\uc74c\uc774 \ud3ec\ud568\ub429\ub2c8\ub2e4.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\ubb34\uc791\uc704 \ubb38\uc790\uc5f4\ub85c \uc774\ub984\uc774 \uc9c0\uc815\ub418\uace0 \uc124\uba85\uc774 &#8216;Sha1-Hulud: The Second Coming&#8217;\uc73c\ub85c \uc124\uc815\ub41c \uc0c8 \uacf5\uac1c \ub9ac\ud3ec\uc9c0\ud130\ub9ac \uc0dd\uc131<\/li>\n\n\n\n<li>\uc774\ub984\uc774 &#8216;SHA1HULUD&#8217;\uc778 \uc790\uccb4 \ud638\uc2a4\ud305 \ub7ec\ub108 \ub4f1\ub85d<\/li>\n\n\n\n<li>GitHub \ub514\uc2a4\ucee4\uc158\uc744 \uc0ac\uc6a9\ud558\uac70\ub098 \uc774\uc640 \uc0c1\ud638\uc791\uc6a9\ud558\ub294 GitHub \uc791\uc5c5 \uc6cc\ud06c\ud50c\ub85c \uc0dd\uc131<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"the-endpoint\">\uc5d4\ub4dc\ud3ec\uc778\ud2b8<\/h3>\n\n\n\n<p>\uc5d4\ub4dc\ud3ec\uc778\ud2b8\uc5d0\uc11c\uc758 \ud0d0\uc9c0\ub97c \uc704\ud55c \ud575\uc2ec\uc801\uc778 \ub85c\uadf8 \uc18c\uc2a4\uc5d0\ub294 \ud30c\uc77c \ubc0f \ud504\ub85c\uc138\uc2a4 \ubaa8\ub2c8\ud130\ub9c1\uc774 \ud3ec\ud568\ub429\ub2c8\ub2e4(\ud504\ub85c\uc138\uc2a4 \ubaa8\ub2c8\ud130\ub9c1\uc5d0\ub294 \uba85\ub839\uc904 \uac10\uc0ac\ub97c \ud3ec\ud568\ud574\uc57c \ud568). \ud0d0\uc9c0 \uae30\ud68c\uc5d0\ub294 \ub2e4\uc74c\uc774 \ud3ec\ud568\ub429\ub2c8\ub2e4.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>setup_bun.js \uc0ac\uc804 \uc124\uce58 \uc2a4\ud06c\ub9bd\ud2b8\uc758 \uc2e4\ud589\uc744 \ubcf4\uc5ec \uc8fc\ub294 \ud504\ub85c\uc138\uc2a4 \ud65c\ub3d9<\/li>\n\n\n\n<li>\uc190\uc0c1\ub41c NPM \ud328\ud0a4\uc9c0\ub97c \ub2e4\uc6b4\ub85c\ub4dc\ud558\uac70\ub098 \uc124\uce58\ud558\ub294 \ud30c\uc77c \ud65c\ub3d9\n<ul class=\"wp-block-list mb-1 mt-2\">\n<li>\uac10\uc5fc\ub41c \ud328\ud0a4\uc9c0 \ubaa9\ub85d\uc740 <a href=\"https:\/\/github.com\/wiz-sec-public\/wiz-research-iocs\/blob\/main\/reports\/shai-hulud-2-packages.csv\" target=\"_blank\" rel=\"noopener\">\uc5ec\uae30<\/a>\uc640 <a href=\"https:\/\/stepsecurity-public-media.s3.us-west-2.amazonaws.com\/website\/blog\/Sha1-Hulud-The-Second-Coming.html\" target=\"_blank\" rel=\"noopener\">\uc5ec\uae30<\/a>\uc5d0\uc11c \ud655\uc778\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\uc601\ud5a5\uc744 \ubc1b\uc740 \uae30\uae30\uc5d0\uc11c \uc0ac\uc6a9\uc790 \ud648 \ub514\ub809\ud130\ub9ac \ub0b4 \ud30c\uc77c\uc744 \ube60\ub974\uac8c \uc0ad\uc81c\ud558\ub294 \ud65c\ub3d9<\/li>\n\n\n\n<li>GitHub Actions\uc6a9 \ub85c\uceec \ub7ec\ub108 \uc124\uce58\uc640 \uad00\ub828\ub41c \ud504\ub85c\uc138\uc2a4 \ud65c\ub3d9<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cloud-providers\">\ud074\ub77c\uc6b0\ub4dc \uc11c\ube44\uc2a4 \uc81c\uacf5\uc5c5\uccb4<\/h3>\n\n\n\n<p>\uc8fc\uc694 \ub85c\uadf8 \uc18c\uc2a4\uc5d0\ub294 AWS CloudTrail \ub85c\uadf8\uc640 Microsoft Entra ID \ub85c\uadf8\uac00 \ud3ec\ud568\ub429\ub2c8\ub2e4. \ud074\ub77c\uc6b0\ub4dc \ub85c\uadf8\ub97c \ud1b5\ud55c \uc8fc\uc694 \ud0d0\uc9c0 \uae30\ud68c\ub294 Trufflehog\uc640 \uac19\uc740 \ub3c4\uad6c\ub97c \uc0ac\uc6a9\ud558\uc5ec \ud074\ub77c\uc6b0\ub4dc \uc790\uaca9 \uc99d\uba85\uc774 \uc218\uc9d1\ub418\ub294 \uc0c1\ud669\uc744 \ud0d0\uc9c0\ud558\ub294 \uac83\uc785\ub2c8\ub2e4.<\/p>\n\n\n\n<p>SHA1-Hulud \uba40\uc6e8\uc5b4 \ubd84\uc11d\uc740 \uacc4\uc18d \uc9c4\ud589 \uc911\uc774\ubbc0\ub85c \uc0c8\ub85c\uc6b4 \uc815\ubcf4\uac00 \ub098\uc62c \uc218 \uc788\uc5b4 \uad00\ub828 \ubd84\uc11d \uc790\ub8cc\ub97c \uc8fc\uae30\uc801\uc73c\ub85c \ub2e4\uc2dc \ud655\uc778\ud558\ub294 \uac83\uc774 \uc88b\uc2b5\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<p>\uc774\uc81c \uc774\ub97c \ud0d0\uc9c0\ud560 \uc218 \uc788\ub294 \uba87 \uac00\uc9c0 \uc8fc\uc694 \ubc29\ubc95\uc744 \uc0b4\ud3b4\ubcf4\uaca0\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<h2 class=\"wp-block-heading mt-4\" id=\"relevant-queries-and-built-in-rules-for-sumo-logic-cloud-siem-customers\">Sumo Logic Cloud SIEM \uace0\uac1d\uc744 \uc704\ud55c \uad00\ub828 \ucffc\ub9ac \ubc0f \uae30\ubcf8 \uc81c\uacf5 \uaddc\uce59<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"github-focused\">GitHub \uae30\ubc18 \ud0d0\uc9c0<\/h3>\n\n\n\n<p>\uc774\ub7ec\ud55c \ud0d0\uc9c0\ub294 GitHub \ud65c\ub3d9\uc5d0 \uc911\uc810\uc744 \ub450\uba70, GitHub Enterprise \uac10\uc0ac \ub85c\uae45\uc774 \ud544\uc694\ud569\ub2c8\ub2e4. GitHub Enterprise \uac10\uc0ac \ub85c\uadf8\ub97c \uc218\uc9d1\ud558\ub294 \ubc29\ubc95\uc740 <a href=\"https:\/\/help.sumologic.com\/docs\/integrations\/app-development\/github\/#collecting-logs-for-github\" target=\"_blank\" rel=\"noopener\">Sumo Logic \ubb38\uc11c<\/a>\ub97c \ucc38\uc870\ud558\uc138\uc694.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\uae30\ubc95: \uc720\ucd9c\ub41c \ube44\ubc00 \uc815\ubcf4\uac00 \ubb34\uc791\uc704 \ubb38\uc790\uc5f4\ub85c \uc774\ub984\uc774 \uc9c0\uc815\ub41c \uc0c8 \uacf5\uac1c \ub9ac\ud3ec\uc9c0\ud130\ub9ac\uc5d0 \uc5c5\ub85c\ub4dc\ub418\uba70, \uc124\uba85\uc740 &#8216;Sha1-Hulud: The Second Coming&#8217;\uc73c\ub85c \uc124\uc815\ub428<\/h6>\n\n\n\n<p><a href=\"https:\/\/www.stepsecurity.io\/blog\/sha1-hulud-the-second-coming-zapier-ens-domains-and-other-prominent-npm-packages-compromised\" target=\"_blank\" rel=\"noopener\">Step Security\uc758 \ubd84\uc11d<\/a>\uc5d0 \ub530\ub974\uba74 SHA1-Hulud\ub294 &#8220;\ud638\uc2a4\ud2b8\uc758 \ud2b9\uc9d5 \uc815\ubcf4\ub97c \uc218\uc9d1\ud558\uace0, \ud074\ub77c\uc6b0\ub4dc \ubcfc\ud2b8\ub97c \ub4a4\uc838 \ube44\ubc00 \uc815\ubcf4\ub97c \ucc3e\uc2b5\ub2c8\ub2e4. \uc774\ud6c4 \uc774\ub7ec\ud55c \ubaa8\ub4e0 \ube44\ubc00 \uc815\ubcf4\ub294 \ubb34\uc791\uc704 UUID \uc774\ub984\uc758 \uc0c8 \uacf5\uac1c \ub9ac\ud3ec\uc9c0\ud130\ub9ac\uc5d0 JSON \ube14\ub86d \ud615\ud0dc\ub85c \uc5c5\ub85c\ub4dc\ub418\uba70 \uc124\uba85\uc740 &#8216;Sha1-Hulud: The Second Coming&#8217;\uc73c\ub85c \uc124\uc815\ub429\ub2c8\ub2e4.&#8221;<\/p>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\ucffc\ub9ac: \uc720\ucd9c\ub41c \uc790\uaca9 \uc99d\uba85\uc73c\ub85c \ub9cc\ub4e4\uc5b4\uc9c4 \ub9ac\ud3ec\uc9c0\ud130\ub9ac \ucc3e\uae30<\/h6>\n\n\n\n<p>\uc774 \ucffc\ub9ac\ub294 \uc9c0\uc815\ub41c \uae30\uac04 \ub0b4\uc5d0 \uc0c8\ub86d\uac8c \uc0dd\uc131\ub41c git \ub9ac\ud3ec\uc9c0\ud130\ub9ac\ub97c \ubc18\ud658\ud569\ub2c8\ub2e4. \uc55e\uc11c \uc5b8\uae09\ud588\ub4ef\uc774 \ub9ac\ud3ec\uc9c0\ud130\ub9ac \uc774\ub984\uc740 &#8216;aoy7angy5kwcq64fb7&#8217;\uacfc \uac19\uc740 \uc784\uc758\uc758 \ubb38\uc790\uc5f4\uc77c \uc218 \uc788\uc73c\uba70, \uc124\uba85\uc740 &#8216;Sha1-Hulud: The Second Coming&#8217;\ucc98\ub7fc \ub418\uc5b4 \uc788\uc744 \uc218 \uc788\uc2b5\ub2c8\ub2e4. \uc774\uc0c1\uc801\uc73c\ub85c\ub294 \uc124\uba85\uc744 \uae30\uc900\uc73c\ub85c \uac80\uc0c9\ud560 \uc218 \uc788\uc73c\uba74 \uc88b\uaca0\uc9c0\ub9cc, <a href=\"https:\/\/docs.github.com\/en\/authentication\/keeping-your-account-and-data-secure\/security-log-events#repo\" target=\"_blank\" rel=\"noopener\">GitHub\uc758 create-repo.create \ub85c\uadf8<\/a>\uc5d0\ub294 \ub9ac\ud3ec\uc9c0\ud130\ub9ac \uc124\uba85\uc774 \ud3ec\ud568\ub418\uc9c0 \uc54a\uc2b5\ub2c8\ub2e4. \ub530\ub77c\uc11c \ucd9c\ub825 \uacb0\uacfc\ub97c \uac80\ud1a0\ud558\uba74\uc11c \uc784\uc758\uc758 \ubb38\uc790\uc5f4 \ud615\ud0dc\uc758 \ub9ac\ud3ec\uc9c0\ud130\ub9ac \uc774\ub984\uc744 \ucc3e\uc544\uc57c \ud558\uba70, \uc774\ub984 \uae38\uc774\uac00 18\uc790 \uc774\uc0c1\uc778 \ub9ac\ud3ec\uc9c0\ud130\ub9ac\ub85c \uac80\uc0c9 \uc870\uac74\uc744 \uad6c\uccb4\ud654\ud558\ub294 \uac83\uc774 \uc88b\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>_index=sec_record_audit metadata_product=\"GitHub Enterprise Audit\" normalizedAction=\"create\"\n| where metadata_deviceEventId = \"create-repo.create\"\n| count by user_username, repository <\/code><\/pre>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\uae30\ubc95: \uc190\uc0c1\ub41c \ud638\uc2a4\ud2b8\uc5d0\uc11c C2 \uba85\ub839\uc744 \uc2e4\ud589\ud558\uae30 \uc704\ud574 &#8216;SHA1HULUD&#8217;\ub77c\ub294 \uc774\ub984\uc758 \uc0c8\ub85c\uc6b4 \uc790\uccb4 \ud638\uc2a4\ud305 \ub7ec\ub108 \uc0dd\uc131<\/h6>\n\n\n\n<p><a href=\"https:\/\/www.wiz.io\/blog\/shai-hulud-2-0-ongoing-supply-chain-attack\" target=\"_blank\" rel=\"noopener\">wiz.io\uc758 \ubd84\uc11d<\/a>\uc5d0 \ub530\ub974\uba74 SHA1-Hulud\ub294 \u201c\uac10\uc5fc\ub41c \uba38\uc2e0\uc744 \u2018SHA1HULUD\u2019\ub77c\ub294 \uc774\ub984\uc758 \uc790\uccb4 \ud638\uc2a4\ud305 \ub7ec\ub108\ub85c \ub4f1\ub85d\ud55c\ub2e4.\u201d\uace0 \ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\ucffc\ub9ac: \uc790\uccb4 \ud638\uc2a4\ud305 \ub7ec\ub108 \ub4f1\ub85d \uac80\ud1a0<\/h6>\n\n\n\n<p>\uc774 \ucffc\ub9ac\ub294 \uc9c0\uc815\ub41c \uae30\uac04 \ub0b4\uc5d0 \ub4f1\ub85d\ub41c \uc790\uccb4 \ud638\uc2a4\ud305 \ub7ec\ub108\ub97c \ubc18\ud658\ud569\ub2c8\ub2e4. \uc704\uc758 \ub9ac\ud3ec\uc9c0\ud130\ub9ac \uc0dd\uc131 \ucffc\ub9ac\uc640 \ub9c8\ucc2c\uac00\uc9c0\ub85c GitHub \ub85c\uadf8\uc5d0\ub294 \ub7ec\ub108 \uc774\ub984\uc774\ub77c\ub294 \uc720\uc6a9\ud55c \uc815\ubcf4\uac00 \ud558\ub098 \ub204\ub77d\ub418\uc5b4 \uc788\uc2b5\ub2c8\ub2e4. \ub530\ub77c\uc11c \ub9ac\ud3ec\uc9c0\ud130\ub9ac, \uc0ac\uc6a9\uc790 \uc774\ub984, \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4 \ub4f1\uc758 \uae30\ud0c0 \uba54\ud0c0\ub370\uc774\ud130\uc5d0\uc11c \ube44\uc815\uc0c1\uc801\uc778 \ud65c\ub3d9\uc774 \uc788\ub294\uc9c0 \uc2a4\uce94\ud574\uc57c \ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>_index=sec_record_audit metadata_product=\"GitHub Enterprise Audit\"\n| where metadata_deviceEventId = \"create-repo.register_self_hosted_runner\"\n| count by repository, user_username<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"endpoint-focused\">\uc5d4\ub4dc\ud3ec\uc778\ud2b8 \uae30\ubc18 \ud0d0\uc9c0<\/h3>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\uae30\ubc95: npm \uc0ac\uc804 \uc124\uce58 \uc2a4\ud06c\ub9bd\ud2b8\ub97c \ud1b5\ud55c \uc545\uc131\ucf54\ub4dc \uc124\uce58<\/h6>\n\n\n\n<p>StepSecurity \ubd84\uc11d\uc5d0 \ub530\ub974\uba74 \uc190\uc0c1\ub41c npm \ud328\ud0a4\uc9c0\ub294 \uc0ac\uc804 \uc124\uce58 \uc2a4\ud06c\ub9bd\ud2b8\ub97c \ud1b5\ud574 SHA1-Hulud\ub97c \uc124\uce58\ud569\ub2c8\ub2e4. \u201c\uacf5\uaca9\uc740 npm\uc774 \ud328\ud0a4\uc9c0\ub97c \uc124\uce58\ud558\ub294 \uc21c\uac04 \uc2dc\uc791\ub418\uba70, package.json\uc758 \ud574\ub2f9 \ud56d\ubaa9\uc5d0 \uc758\ud574 \ud2b8\ub9ac\uac70\ub41c\ub2e4&#8221;\uace0 \ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>{\n  \"scripts\": {\n    \"preinstall\": \"node setup_bun.js\"\n  }\n}<\/code><\/pre>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\ucffc\ub9ac: SHA1-Hulud \uc0ac\uc804 \uc124\uce58 \uc2a4\ud06c\ub9bd\ud2b8\uc758 \uba85\ub839\uc904 \ud0d0\uc0c9<\/h6>\n\n\n\n<p>\uc544\ub798 \ucffc\ub9ac\ub294 SHA1-Hulud \uc0ac\uc804 \uc124\uce58 \uc2a4\ud06c\ub9bd\ud2b8\uc758 \uba85\ub839\uc904\uacfc \uc77c\uce58\ud558\ub294 \ud504\ub85c\uc138\uc2a4 \uc0dd\uc131 \ub808\ucf54\ub4dc\ub97c \uac80\uc0c9\ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>_index=sec_record_endpoint action=\"ProcessCreate\"\n| where commandLine matches \/node\\s+setup_bun\\.js\/<\/code><\/pre>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\uae30\ubc95: \uc0ac\uc6a9\uc790 \ud648 \ub514\ub809\ud130\ub9ac\uc5d0\uc11c \uc4f0\uae30 \uac00\ub2a5\ud55c \ud30c\uc77c \uc0ad\uc81c<\/h6>\n\n\n\n<p><a href=\"https:\/\/www.koi.ai\/incident\/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised\" target=\"_blank\" rel=\"noopener\">Koi\uc758 \ubd84\uc11d<\/a>\uc5d0 \ub530\ub974\uba74, &#8220;\uba40\uc6e8\uc5b4\uac00 \uc778\uc99d\uc5d0 \uc2e4\ud328\ud558\uac70\ub098 \uc9c0\uc18d\uc131\uc744 \ud655\ubcf4\ud558\uc9c0 \ubabb\ud558\uba74 \ud53c\ud574\uc790\uc758 \ud648 \ub514\ub809\ud130\ub9ac \uc804\uccb4\ub97c \ud30c\uad34\ud558\ub824 \ud569\ub2c8\ub2e4. \uad6c\uccb4\uc801\uc73c\ub85c\ub294 \ud604\uc7ac \uc0ac\uc6a9\uc790\uac00 \uc18c\uc720\ud55c \ud648 \ud3f4\ub354 \ub0b4\uc758 \ubaa8\ub4e0 \uc4f0\uae30 \uac00\ub2a5\ud55c \ud30c\uc77c\uc744 \uc0ad\uc81c\ud569\ub2c8\ub2e4.&#8221;<\/p>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\ucffc\ub9ac: \uc0ac\uc6a9\uc790\uc758 \ud648 \ub514\ub809\ud130\ub9ac\uc5d0\uc11c\uc758 \ud30c\uc77c \uc0ad\uc81c \uc218(Windows)<\/h6>\n\n\n\n<p>\uc544\ub798 \ucffc\ub9ac\ub294 \uc0ac\uc6a9\uc790 \ud648 \ub514\ub809\ud130\ub9ac\uc5d0\uc11c \ubc1c\uc0dd\ud55c \ud30c\uc77c \uc0ad\uc81c \uc774\ubca4\ud2b8\ub97c \ucc3e\uae30 \uc704\ud574 \uc774\ubca4\ud2b8 ID 23 \ub610\ub294 26(\ud30c\uc77c \uc0ad\uc81c \uc774\ubca4\ud2b8)\uc5d0 \ud574\ub2f9\ud558\ub294 Microsoft Sysmon \ub85c\uadf8\ub97c \uac80\uc0c9\ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>_index=sec_record_endpoint\n| where metadata_deviceeventId = \"Microsoft-Windows-Sysmon\/Operational-23\" or metadata_deviceeventid = \"Microsoft-Windows-Sysmon\/Operational-26\"\n| where changetarget matches \/C:\\\\Users.*\/\n| count by device_hostname<\/code><\/pre>\n\n\n\n<p>\ucc38\uace0: \uc774\uc0c1\uc801\uc73c\ub85c\ub294 \uad00\uc2ec \ub300\uc0c1 \ud30c\uc77c \ud65c\ub3d9\uc744 <a href=\"https:\/\/learn.microsoft.com\/en-us\/sysinternals\/downloads\/sysmon\" target=\"_blank\" rel=\"noopener\">Microsoft Sysmon<\/a>(\uc774\ubca4\ud2b8 ID 23)\uc774\ub098 <a href=\"https:\/\/learn.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-10\/security\/threat-protection\/auditing\/audit-file-system\" target=\"_blank\" rel=\"noopener\">Microsoft \uac1c\uccb4 \uc561\uc138\uc2a4 \uac10\uc0ac<\/a>(\uc774\ubca4\ud2b8 ID <a href=\"https:\/\/learn.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-10\/security\/threat-protection\/auditing\/event-4660\" target=\"_blank\" rel=\"noopener\">4600<\/a> \ubc0f <a href=\"https:\/\/learn.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-10\/security\/threat-protection\/auditing\/event-4663\" target=\"_blank\" rel=\"noopener\">4663<\/a>)\uc640 \uac19\uc740 \ub85c\uadf8 \uc18c\uc2a4\ub97c \ud1b5\ud55c \ud30c\uc77c \uc2dc\uc2a4\ud15c \ubaa8\ub2c8\ud130\ub9c1\uc73c\ub85c \ud0d0\uc9c0\ud558\ub294 \uac83\uc774 \uac00\uc7a5 \uc88b\uc2b5\ub2c8\ub2e4. \uadf8\ub7ec\ub098 \uad00\uc2ec \uc788\ub294 \ub514\ub809\ud130\ub9ac\uac00 \uac10\uc0ac \ub300\uc0c1\uc73c\ub85c \uad6c\uc131\ub418\uc5b4 \uc788\uc5b4\uc57c \ud569\ub2c8\ub2e4. \ub2e4\uc2dc \ub9d0\ud574 \ubaa8\ub4e0 \ud30c\uc77c \ud65c\ub3d9\uc774 \ub85c\uadf8\ub85c \ub0a8\ub294\ub2e4\uace0 \ubcf4\uc7a5\ud558\uae30\ub294 \uc5b4\ub835\uc2b5\ub2c8\ub2e4. \ub530\ub77c\uc11c \ub2e4\ub978 \ub85c\uadf8 \uc18c\uc2a4 \uc720\ud615\uc5d0 \uc758\uc874\ud574\uc57c \ud560 \uc218\ub3c4 \uc788\uc2b5\ub2c8\ub2e4. \uc774 \uacbd\uc6b0 Koi\uc758 \uac8c\uc2dc\ubb3c\uc5d0\uc11c \uc5b8\uae09\ub41c \uba85\ub839\uc904\uc744 \uac80\uc0c9\ud574 \ubcfc \uac83\uc785\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\ucffc\ub9ac: \ud648 \ub514\ub809\ud130\ub9ac\uc5d0\uc11c \ud30c\uc77c \uc0ad\uc81c\ub97c \ub098\ud0c0\ub0b4\ub294 \uba85\ub839\uc904(Windows)<\/h6>\n\n\n\n<p>\uc544\ub798 \ucffc\ub9ac\ub294 SHA1-Hulud\uac00 \uc0ac\uc6a9\ud558\ub294 \uac83\uc73c\ub85c \uc54c\ub824\uc9c4 \uba85\ub839\uc904(\uc815\uaddc\uc2dd \uae30\ubc18)\uacfc \uc77c\uce58\ud558\ub294 \ud504\ub85c\uc138\uc2a4 \uc0dd\uc131 \ub85c\uadf8\ub97c \uac80\uc0c9\ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>_index=sec_record_endpoint action=\"ProcessCreate\"\n| where commandLine matches \/del\\s+\\\/F\\s+\\\/Q\\s+\\\/S\\s+C:\\\\Users\/<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cloud-focused\">\ud074\ub77c\uc6b0\ub4dc \uae30\ubc18 \ud0d0\uc9c0<\/h3>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\uae30\ubc95: Trufflehog\uc744 \uc0ac\uc6a9\ud55c \ud074\ub77c\uc6b0\ub4dc \uc790\uaca9 \uc99d\uba85 \uc218\uc9d1<\/h6>\n\n\n\n<p><a href=\"https:\/\/www.aikido.dev\/blog\/shai-hulud-strikes-again-hitting-zapier-ensdomains\" target=\"_blank\" rel=\"noopener\">Aikido<\/a> \ubd84\uc11d\uc5d0 \ub530\ub974\uba74, \u201c\uc774 \uc545\uc131\ucf54\ub4dc\ub294 \uc774\ud6c4 \uc790\ub3d9\ud654 \ub3c4\uad6c(TruffleHog)\ub97c \uc0ac\uc6a9\ud574 \ube44\ubc00\ubc88\ud638, API \ud0a4, \ud074\ub77c\uc6b0\ub4dc \ud1a0\ud070, GitHub \ub610\ub294 NPM \uc790\uaca9 \uc99d\uba85 \uac19\uc740 \ubbfc\uac10 \uc815\ubcf4\ub97c \uac80\uc0c9\ud55c\ub2e4\u201d\uace0 \ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\" id=\"technique-exfiltrated-secrets-are-uploaded-to-a-new-public-repo-named-after-a-random-uuid-with-description-sha1-hulud-the-second-coming\">\uaddc\uce59: Trufflehog \uc0ac\uc6a9 \ubc0f \ud074\ub77c\uc6b0\ub4dc \ube44\ubc00 \uc815\ubcf4 \uc5f4\uac70 \ud0d0\uc9c0\uc6a9 Sumo Logic \uaddc\uce59<\/h6>\n\n\n\n<p>Sumo Logic\uc740 Trufflehog \uc0ac\uc6a9\uc744 \ud3ec\ud568\ud558\uc5ec \ube44\ubc00 \uc815\ubcf4 \uc218\uc9d1 \ud65c\ub3d9\uc744 \ud0d0\uc9c0\ud558\uae30 \uc704\ud55c \uc5ec\ub7ec SIEM \uaddc\uce59\uc744 \uc81c\uacf5\ud569\ub2c8\ub2e4. \uc608\uc2dc\ub294 \ub2e4\uc74c\uacfc \uac19\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>&#8211; Trufflehog AWS \uc790\uaca9 \uc99d\uba85 \uac80\uc99d \ud0d0\uc9c0: MATCH-S00925<\/p>\n\n\n\n<p>&#8211; \ucd5c\ucd08 \ud0d0\uc9c0 IP \uc8fc\uc18c \uc2e4\ud589 Trufflehog AWS \uc790\uaca9 \uc99d\uba85: FIRST-S00086<\/p>\n\n\n\n<p>&#8211; AWS CloudTrail \u2013 \ube44 Amazon IP\uc5d0\uc11c \ube44\ubc00\uac12 \ud68d\ub4dd: MATCH-S00246<\/p>\n\n\n\n<p>&#8211; AWS Secrets Manager \uc77c\ub78c\ud45c: MATCH-S00825<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"recommended-mitigation-and-remediation-steps\">\uad8c\uc7a5 \ub300\uc751 \ubc0f \ubcf5\uad6c \ub2e8\uacc4<\/h2>\n\n\n\n<p>Panther Labs, StepSecurity, Aikido \ub4f1\uc5d0\uc11c \uc81c\uacf5\ud558\ub294 \uc5ec\ub7ec \ucc38\uace0 \uc790\ub8cc\uc5d0\ub294 \uc2dc\ud06c\ub9bf \ud0a4 \ub85c\ud14c\uc774\uc158, \uc790\uccb4 \ud638\uc2a4\ud305 \ub7ec\ub108 \uc0ad\uc81c, npm \ud328\ud0a4\uc9c0 \uc0ac\uc6a9 \ub0b4\uc5ed \uac10\uc0ac, CI\/CD \ub85c\uadf8 \uac80\ud1a0, \ub9ac\ud3ec\uc9c0\ud130\ub9ac \uc0dd\uc131 \uc774\ub825 \uac80\ud1a0 \ub4f1\uacfc \uac19\uc740 \uc0c1\uc138 \uc870\uce58 \ubc29\uc548\uc774 \uc18c\uac1c\ub418\uc5b4 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"final-thoughts\">\ub9fa\uc74c\ub9d0<\/h2>\n\n\n\n<p>SHA1-Hulud \uacf5\uaca9\uc740 \uc870\uc9c1 \ub0b4\uc5d0\uc11c \uc0ac\uc6a9\ub418\ub294 \ub2e4\uc591\ud55c \uae30\uc220(\uc5d4\ub4dc\ud3ec\uc778\ud2b8\ubfd0\ub9cc \uc544\ub2c8\ub77c CI\/CD \ud30c\uc774\ud504\ub77c\uc778\uacfc \ud074\ub77c\uc6b0\ub4dc \ud658\uacbd \ud3ec\ud568)\uc744 \ud3ec\uad04\ud558\ub294 \uc885\ud569\uc801\uc778 \ub85c\uae45\uc758 \uc911\uc694\uc131\uc744 \ub2e4\uc2dc \ud55c\ubc88 \uc0c1\uae30\uc2dc\ucf1c \uc8fc\ub294 \uc0ac\ub840\uc785\ub2c8\ub2e4. \ud3ec\uad04\uc801\uc778 \ub85c\uae45\uc744 \ud1b5\ud574 \ub85c\uadf8 \uc18c\uc2a4\uc758 \uad00\uc810\uc5d0\uc11c \uac00\uc7a5 \uc801\ud569\ud55c \ud0d0\uc9c0 \uaddc\uce59\uc744 \ud65c\uc6a9\ud560 \uc218 \uc788\uc73c\uba70, \uc774\ub97c \ud1b5\ud574 \ubcf5\uc7a1\ud55c \uacf5\uaca9\uc744 \uc870\uae30\uc5d0 \ud0d0\uc9c0\ud560 \uac00\ub2a5\uc131\uc744 \uadf9\ub300\ud654\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n<div class=\"e-btn e-btn--blue-button-with-right-arrow\"><a class=\"e-btn__link\" href=\"https:\/\/www.sumologic.com\/request-demo\" target=\"_self\">\n<p class=\"title\">\ud074\ub77c\uc6b0\ub4dc SIEM\uc5d0 \ub300\ud574 \ub354 \uc54c\uc544\ubcf4\uae30<\/p>\n<\/a><\/div>\n\n\n<style>\n.e-div--card-btn-link a.e-btn__link {color: #fff!important; text-decoration: none!important; cursor: pointer;}\n.e-div--card-btn-link .e-btn--blue-button-with-right-arrow,\n.e-div--card-btn-link .e-btn--blue-button-with-right-arrow p.title {cursor: pointer;}\n<\/style>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":332,"featured_media":62046,"template":"","meta":{"_acf_changed":false,"show_custom_date":false,"custom_date":"","featured":false,"featured_image":0,"learn_more_label":"","image_alt_text":"","learn_more_type":"","show_popup":false,"learn_more_link_file":0,"event_date":false,"event_start_date":"","event_end_date":"","place_holder_image_url":"","post_reading_time":"2","notification_enabled":false,"notification_text":"","notification_logo":"","notification_expiration_time":0,"is_enable_transparent_header":false,"selected_taxonomy_terms":{"blog-category":[320,325],"blog-tag":[],"translation_priority":[221]},"selected_primary_terms":[],"learn_more_link":[],"featured_page_list":[],"notification_enabled_post_list":[],"_gspb_post_css":"","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"55110,62715,62708","_relevanssi_noindex_reason":"","inline_featured_image":false,"footnotes":""},"blog-category":[320,325],"blog-tag":[],"class_list":["post-62740","blog","type-blog","status-publish","has-post-thumbnail","hentry","blog-category-secops-security","blog-category-cloud-siem"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog\/62740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/users\/332"}],"version-history":[{"count":5,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog\/62740\/revisions"}],"predecessor-version":[{"id":67542,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog\/62740\/revisions\/67542"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/media\/62046"}],"wp:attachment":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/media?parent=62740"}],"wp:term":[{"taxonomy":"blog-category","embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog-category?post=62740"},{"taxonomy":"blog-tag","embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog-tag?post=62740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}