<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DDoS · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/ddos/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Sat, 01 Aug 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/ddos/index.xml" rel="self" type="application/rss+xml"/><item><title>Fresh out of the oven</title><link>https://blog.efespain.com/en/chapter-17/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-17/</guid><description>A quiet Sunday, my new-binary alarm went off after days of silence. The first thought was the best one there is: something fresh. What followed was a rollercoaster — an old acquaintance, a false positive that nearly fooled me, and finally a critter that wasn't in any public repository, caught less than thirty hours after it was born.</description></item><item><title>The tenant who'd been there eleven years</title><link>https://blog.efespain.com/en/chapter-16/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-16/</guid><description>A bot walked into my honeypot, stayed 62 seconds and left. I filed it as Gafgyt and I was wrong. A week later I followed its command servers and ended up inside an operation that has been running since 2015 — one I'd had in my hands from day one.</description></item><item><title>KHserver</title><link>https://blog.efespain.com/en/khserver/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/khserver/</guid><description><p><strong>KHserver</strong> has no name in any repository: antivirus engines file it as<em>gafgyt/tsunami</em> and that is where its record ends. I name it after the two marks its own author left compiled inside the binary,<strong><code>KHserverHACKER</code></strong> and<strong><code>KHcommSOCK</code></strong>, because those survive even when the files it hands out are renamed.</p><p>What sets it apart from<a href="/en/mirai/">Mirai</a> or<a href="/en/xorddos/">XorDDoS</a> is not the technique — the skeleton is the usual one — but<strong>the business</strong>. Its command list includes<code>FORTNITE</code>,<code>COD</code>,<code>R6</code>,<code>RUST</code> and<code>VSE</code>, plus two commands aimed at<strong>OVH</strong> and<strong>NFOservers</strong>, the two big game-server hosts. This is not used for whatever comes up:<strong>it is rented by the hour so that somebody&rsquo;s match goes down</strong>.</p></description></item><item><title>Nikki, you are loved</title><link>https://blog.efespain.com/en/chapter-12/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-12/</guid><description>The binary arrived unstripped: its author left inside the names of all six hundred and twenty-eight functions he wrote. It is like being handed a closed book with the index stapled to the cover. Here I read it end to end, function by function, until I reach the one string that fitted nowhere.</description></item><item><title>The bot that bragged — and couldn't be bothered</title><link>https://blog.efespain.com/en/chapter-11/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-11/</guid><description>A 1,177-byte loader landed: nine lines of wget, one per architecture, in the style I have already opened three times on this blog. I was going to file it as a repeat offender and get on with my day. I opened it anyway, out of habit — and the first thing I saw was that it had a few characters too many.</description></item><item><title>Someone brought their malware to my house</title><link>https://blog.efespain.com/en/chapter-1/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-1/</guid><description>I keep a honeypot in some corner of the network. Most of it is noise: scanners that look and leave. Until one got in, decided it was the administrator, and pushed its critter up through the service door.</description></item><item><title>The botnet that left its code out in the open</title><link>https://blog.efespain.com/en/chapter-3/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-3/</guid><description>Another one walks in and drops its critter. But this one left a door open on its own delivery server — and inside was the source code. A multi-architecture Mirai, caught red-handed.</description></item><item><title>The one that came in through the debug cable</title><link>https://blog.efespain.com/en/chapter-7/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-7/</guid><description>The previous three went after servers. This one went after a phone: it came in through ADB, wiped out the competition, installed its app disguised as Google, and hid itself. First Android malware in the honeypot.</description></item></channel></rss>