<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spoofing · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/spoofing/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Sat, 01 Aug 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/spoofing/index.xml" rel="self" type="application/rss+xml"/><item><title>Cracking XorDDoS open with Ghidra</title><link>https://blog.efespain.com/en/chapter-2/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-2/</guid><description>In Chapter 1 the C2 stayed encrypted inside the binary. Here I open it with Ghidra and it comes out whole — but on the way, everything else this critter carries turns up too: how it disguises itself as a system process, how it kills the competition using the very trail that gives it away, and how it lies about its own address when its command centre tells it to.</description></item></channel></rss>