<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DIICOT · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/diicot/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Tue, 01 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/diicot/index.xml" rel="self" type="application/rss+xml"/><item><title>Only the leader talks</title><link>https://blog.efespain.com/en/chapter-27/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-27/</guid><description>The kit sat still on the disk, so I switched it on myself in a cage with no way out. Inside there's a bot that insists on knowing its own address before anything else, joins a mesh of up to two thousand nodes, holds an election and crowns itself leader — and only then opens a Telegram chat. The operator never logs into any machine: he sends a message to the head of the pack. And when you burn the chat, the botnet heals itself.</description></item><item><title>Sixty-six seconds</title><link>https://blog.efespain.com/en/chapter-26/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-26/</guid><description>The family from the previous chapter didn't stand still: there's a newer build going around, and I caught it from the first second. It brute-forces its way in over SSH, sizes the machine up, evicts the competition —its own older version included—, uploads sixteen megabytes in a single file and fires. All in a little over a minute. And then it walks straight into one line of fstab.</description></item><item><title>The wallet that never travels</title><link>https://blog.efespain.com/en/chapter-28/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-28/</guid><description>The two previous chapters left the kit taken apart piece by piece, and one question unanswered: who it pays. I went looking. And what I found was a design that prevents it — the mining config never travels inside the critter, it gets downloaded afterwards — and scaffolding somebody had already dismantled. This is the chase, what it does plant when you let it run, and how far what I can prove about who's behind it actually goes.</description></item><item><title>The line nobody wrote</title><link>https://blog.efespain.com/en/chapter-24/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-24/</guid><description>The previous chapter left a number unexplained: the backdoor was deleting a different process on every installation, and that can't be known in advance. I open the miner and the answer shows up — a template with the gap already reserved. Along the way out comes the wallet the money goes to, behind encryption that's frankly laughable.</description></item><item><title>Twenty-odd dollars a day</title><link>https://blog.efespain.com/en/chapter-25/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-25/</guid><description>The teardown left me a Monero wallet and a question the binary doesn't answer: how much has this thing earned. Monero is built so no balance can be looked up — but the pool they mine against publishes per-wallet statistics, and that's an open page. What turned up when I asked: one wallet collecting since January 2021, another already running months before it showed up in any sample, about twenty-three dollars a day, and an electricity bill paid by the victims that comes to more than the operator makes.</description></item><item><title>The command that lies</title><link>https://blog.efespain.com/en/chapter-23/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-23/</guid><description>I left a password sitting on a decoy and, one Sunday, something came through it three times. I neutralised what it brought; what I didn't see until later was what it left planted — a line in .bashrc that makes «top» lie and hide the very process eating the machine. A rootkit without a rootkit. And putting two frozen disks side by side turned up the detail that changes everything: the same line, with a different number.</description></item></channel></rss>