<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>IoT · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/iot/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Tue, 01 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/iot/index.xml" rel="self" type="application/rss+xml"/><item><title>Introduced by its enemy</title><link>https://blog.efespain.com/en/chapter-21/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-21/</guid><description>An automated scanner found the honeypot's telnet and, eighteen seconds later, there was a binary inside. The password was «telnet». The loader it dropped comes with two operator typos, one of which breaks an entire infection. And when I finally put a name to the family —IranBot, a Mirai fork with a public dossier— it turned out that name had been written on this blog since August: a rival bot had put it there, in the list of competitors it uninstalls on arrival.</description></item><item><title>A Mirai that couldn't attack?</title><link>https://blog.efespain.com/en/chapter-19/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-19/</guid><description>I pulled down the three binaries from the previous chapter expecting the usual DDoS arsenal. It wasn't there: not one attack function. What it does instead —and above all, the channel its orders arrive on— is the strangest thing that has come through the honeypot. A bug designed, top to bottom, not to be seen.</description></item><item><title>Nothing to file</title><link>https://blog.efespain.com/en/chapter-18/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-18/</guid><description>An already-infected IP connected to the honeypot's telnet and pasted a recipe all at once: eleven binaries, one per architecture, each with a made-up name that will never come round again. Two weighed exactly the same and looked like variants — they turned out to be the i586 and i686 builds of the same program. And behind them wasn't a stray bug: fifty-odd distinct binaries in two weeks. The whole delivery is built so that no blocklist, by name or by signature, catches anything.</description></item><item><title>Fresh out of the oven</title><link>https://blog.efespain.com/en/chapter-17/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-17/</guid><description>A quiet Sunday, my new-binary alarm went off after days of silence. The first thought was the best one there is: something fresh. What followed was a rollercoaster — an old acquaintance, a false positive that nearly fooled me, and finally a critter that wasn't in any public repository, caught less than thirty hours after it was born.</description></item><item><title>KHserver</title><link>https://blog.efespain.com/en/khserver/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/khserver/</guid><description><p><strong>KHserver</strong> has no name in any repository: antivirus engines file it as<em>gafgyt/tsunami</em> and that is where its record ends. I name it after the two marks its own author left compiled inside the binary,<strong><code>KHserverHACKER</code></strong> and<strong><code>KHcommSOCK</code></strong>, because those survive even when the files it hands out are renamed.</p><p>What sets it apart from<a href="/en/mirai/">Mirai</a> or<a href="/en/xorddos/">XorDDoS</a> is not the technique — the skeleton is the usual one — but<strong>the business</strong>. Its command list includes<code>FORTNITE</code>,<code>COD</code>,<code>R6</code>,<code>RUST</code> and<code>VSE</code>, plus two commands aimed at<strong>OVH</strong> and<strong>NFOservers</strong>, the two big game-server hosts. This is not used for whatever comes up:<strong>it is rented by the hour so that somebody&rsquo;s match goes down</strong>.</p></description></item><item><title>The bot that bragged — and couldn't be bothered</title><link>https://blog.efespain.com/en/chapter-11/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-11/</guid><description>A 1,177-byte loader landed: nine lines of wget, one per architecture, in the style I have already opened three times on this blog. I was going to file it as a repeat offender and get on with my day. I opened it anyway, out of habit — and the first thing I saw was that it had a few characters too many.</description></item><item><title>The botnet that left its code out in the open</title><link>https://blog.efespain.com/en/chapter-3/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-3/</guid><description>Another one walks in and drops its critter. But this one left a door open on its own delivery server — and inside was the source code. A multi-architecture Mirai, caught red-handed.</description></item></channel></rss>