<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Static analysis · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/static-analysis/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Tue, 01 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/static-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>The line nobody wrote</title><link>https://blog.efespain.com/en/chapter-24/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-24/</guid><description>The previous chapter left a number unexplained: the backdoor was deleting a different process on every installation, and that can't be known in advance. I open the miner and the answer shows up — a template with the gap already reserved. Along the way out comes the wallet the money goes to, behind encryption that's frankly laughable.</description></item><item><title>Cracking XorDDoS open with Ghidra</title><link>https://blog.efespain.com/en/chapter-2/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-2/</guid><description>In Chapter 1 the C2 stayed encrypted inside the binary. Here I open it with Ghidra and it comes out whole — but on the way, everything else this critter carries turns up too: how it disguises itself as a system process, how it kills the competition using the very trail that gives it away, and how it lies about its own address when its command centre tells it to.</description></item><item><title>Someone brought their malware to my house</title><link>https://blog.efespain.com/en/chapter-1/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-1/</guid><description>I keep a honeypot in some corner of the network. Most of it is noise: scanners that look and leave. Until one got in, decided it was the administrator, and pushed its critter up through the service door.</description></item><item><title>The botnet that left its code out in the open</title><link>https://blog.efespain.com/en/chapter-3/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-3/</guid><description>Another one walks in and drops its critter. But this one left a door open on its own delivery server — and inside was the source code. A multi-architecture Mirai, caught red-handed.</description></item></channel></rss>