<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mirai · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/mirai/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Tue, 01 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/mirai/index.xml" rel="self" type="application/rss+xml"/><item><title>The twin I was missing</title><link>https://blog.efespain.com/en/chapter-22/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-22/</guid><description>A bot of the Mirai school carries the address of whoever gives it orders. I looked for this one's by four different routes and found it by none — and along the way I published a theory of my own that turned out to be false. What finally worked wasn't a better tool: it was realising that somewhere out there sat another binary, compiled from the same code, whose command centre somebody had already published. With both in front of me, the difference between them is one thousand one hundred and thirty bytes.</description></item><item><title>Introduced by its enemy</title><link>https://blog.efespain.com/en/chapter-21/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-21/</guid><description>An automated scanner found the honeypot's telnet and, eighteen seconds later, there was a binary inside. The password was «telnet». The loader it dropped comes with two operator typos, one of which breaks an entire infection. And when I finally put a name to the family —IranBot, a Mirai fork with a public dossier— it turned out that name had been written on this blog since August: a rival bot had put it there, in the list of competitors it uninstalls on arrival.</description></item><item><title>Fresh out of the oven</title><link>https://blog.efespain.com/en/chapter-17/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-17/</guid><description>A quiet Sunday, my new-binary alarm went off after days of silence. The first thought was the best one there is: something fresh. What followed was a rollercoaster — an old acquaintance, a false positive that nearly fooled me, and finally a critter that wasn't in any public repository, caught less than thirty hours after it was born.</description></item><item><title>KHserver</title><link>https://blog.efespain.com/en/khserver/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/khserver/</guid><description><p><strong>KHserver</strong> has no name in any repository: antivirus engines file it as<em>gafgyt/tsunami</em> and that is where its record ends. I name it after the two marks its own author left compiled inside the binary,<strong><code>KHserverHACKER</code></strong> and<strong><code>KHcommSOCK</code></strong>, because those survive even when the files it hands out are renamed.</p><p>What sets it apart from<a href="/en/mirai/">Mirai</a> or<a href="/en/xorddos/">XorDDoS</a> is not the technique — the skeleton is the usual one — but<strong>the business</strong>. Its command list includes<code>FORTNITE</code>,<code>COD</code>,<code>R6</code>,<code>RUST</code> and<code>VSE</code>, plus two commands aimed at<strong>OVH</strong> and<strong>NFOservers</strong>, the two big game-server hosts. This is not used for whatever comes up:<strong>it is rented by the hour so that somebody&rsquo;s match goes down</strong>.</p></description></item></channel></rss>