<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SIP · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/sip/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Sat, 01 Aug 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/sip/index.xml" rel="self" type="application/rss+xml"/><item><title>The call factory</title><link>https://blog.efespain.com/en/chapter-14/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-14/</guid><description>In chapter 9 someone tried to make my phone switch pay for their calls. I wrote it up and closed the incident, with one question left hanging: who was on the other end? This time I didn't just watch through the window. I gave the decoy a memory, followed the number's trail, and found out why they pick exactly those numbers.</description></item><item><title>The one who wanted me to pay for their calls</title><link>https://blog.efespain.com/en/chapter-9/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-9/</guid><description>This time no binary landed. A fraud did: for two hours, fifteen machines tried to make my PBX place 3,457 international calls — the trial run of an International Revenue Share Fraud (IRSF), with the bill in my name. A chapter with no Ghidra: just protocol, money and OSINT.</description></item></channel></rss>