<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Honeypots on Pablo Seoane · Pentester &amp; Security Researcher</title><link>https://bardlaudian.github.io/honeypot/</link><description>Recent content in Honeypots on Pablo Seoane · Pentester &amp; Security Researcher</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><copyright>© 2026</copyright><lastBuildDate>Mon, 10 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bardlaudian.github.io/honeypot/index.xml" rel="self" type="application/rss+xml"/><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Aug 2–9, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-05/</link><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-05/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Fifth weekly report from the T-Pot honeypot, period &lt;strong>August 2–9, 2026&lt;/strong>. Volume rises to &lt;strong>~2,814,000 events&lt;/strong>. The residential ConPot botnet reaches its &lt;strong>third consecutive week with now-global reach&lt;/strong> (NTT DOCOMO, Wind Tre, Bouygues Telecom joining the already known Comcast, AT&amp;amp;T, Charter). RDPHoneypot nearly matches its historical maximum driven by a new actor: &lt;strong>Datacamp Limited&lt;/strong>. Cowrie sees a cryptocurrency credential wave and a new malware family named &lt;code>iran&lt;/code> for the first time. And the Adbhoney campaign tracked since the first report — 110→228→287→102 downloads — &lt;strong>closes definitively&lt;/strong>.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> August 2–9, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous reports:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >Jul 7–11&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-02/" >Jul 12–18&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-03/" >Jul 19–25&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-04/" >Jul 26–Aug 2&lt;/a>&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 26 – Aug 2, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-04/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-04/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Fourth weekly report from the T-Pot honeypot, period &lt;strong>July 26 – August 2, 2026&lt;/strong>. With four weeks of accumulated data, patterns stop being anecdotal and become trends: the &lt;strong>residential SNMP botnet on ConPot is confirmed for a second consecutive week&lt;/strong> (Comcast, AT&amp;amp;T, Verizon, Charter with not a single VPS in the top 10), IP &lt;strong>&lt;code>91.199.133.133&lt;/code> catalogued in ThreatFox as a Mirai Katana C2 reappears&lt;/strong> serving payloads in Cowrie, &lt;strong>Redtail adds RISC-V architecture&lt;/strong>, and the brute force campaign against Turkish ERP software in Dionaea is confirmed with a second week of consistent data.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 26 – August 2, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous reports:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >Jul 7–11&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-02/" >Jul 12–18&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-03/" >Jul 19–25&lt;/a>&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 19–25, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-03/</link><pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-03/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Third weekly report from the T-Pot honeypot, period &lt;strong>July 19–25, 2026&lt;/strong>. Total volume drops to &lt;strong>~1,820,000 events&lt;/strong> (half of last week), but the relevant data isn&amp;rsquo;t the total — it&amp;rsquo;s the composition: &lt;strong>ConPot spikes x27&lt;/strong> with origin in residential ISPs (Comcast, AT&amp;amp;T, Virgin Media, Free SAS) — the signature of a domestic router botnet attacking SNMP, a qualitatively different actor from anything seen so far. Meanwhile, Flyservers S.A. collapses on RDP, the same Adbhoney payload is in its third week of growth, and Dionaea detects brute force specifically targeting Turkish accounting software over MSSQL.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 19–25, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous reports:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >Jul 7–11&lt;/a> · &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-02/" >Jul 12–18&lt;/a>&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 12–18, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-02/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-02/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 Second weekly report from the T-Pot honeypot, period &lt;strong>July 12–18, 2026&lt;/strong>. Total volume spikes to &lt;strong>~3,213,000 events&lt;/strong> (x3.2 compared to the previous week), but growth is not uniform: it&amp;rsquo;s almost entirely explained by two sensors — &lt;strong>RDPHoneypot x20.7&lt;/strong> with Flyservers S.A. as the dominant source, and &lt;strong>Sentrypeer x9.3&lt;/strong> with a target shift toward UK numbering. Recurring actors are confirmed across multiple sensors, and a new loader compiled for unusual architectures (&lt;code>loongarch64&lt;/code>, &lt;code>m68k&lt;/code>) is identified.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 12–18, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR
&lt;strong>Previous report:&lt;/strong> &lt;a href="https://bardlaudian.github.io/honeypot/informe-semanal-01/" >week of July 7–11, 2026&lt;/a>&lt;/p></description></item><item><title>Weekly Threat Intelligence Report — T-Pot Honeypot (Jul 7–11, 2026)</title><link>https://bardlaudian.github.io/honeypot/informe-semanal-01/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/informe-semanal-01/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 First weekly report from the T-Pot honeypot. During the week of &lt;strong>July 7–11, 2026&lt;/strong>, approximately &lt;strong>1,011,000 attack events&lt;/strong> were recorded across 10 active sensors. Top findings: multi-architecture &lt;em>Redtail&lt;/em> malware captured in Cowrie, a complete Android infection chain in Adbhoney (Rebirth → UFO miner → Trinity botnet), active scanning of exposed AI services (Ollama, Gradio, Streamlit), and probing of the IEC-104 protocol used in European electrical substations.
&lt;/div>

&lt;hr>
&lt;p>&lt;strong>Period analyzed:&lt;/strong> July 7–11, 2026
&lt;strong>Source:&lt;/strong> T-Pot (multi-honeypot + ELK Stack) — publicly internet-exposed instance
&lt;strong>Classification:&lt;/strong> Portfolio use / TLP:CLEAR&lt;/p></description></item><item><title>I Captured a Rebirth Botnet Sample in My Honeypot: Here's What I Pieced Together</title><link>https://bardlaudian.github.io/honeypot/rebirth-botnet/</link><pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/rebirth-botnet/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 While reviewing traffic from my T-Pot honeypot I found something more interesting than the typical SSH brute-force attempt: a complete infection chain, captured live, that turned out to be a variant of the &lt;strong>Rebirth&lt;/strong> botnet, from the Mirai/Gafgyt family. This post covers exactly what I captured, how I pieced it together to identify it, and what the security community says about this family — making clear throughout what is my direct observation and what is third-party research.
&lt;/div>

&lt;hr>

&lt;h2 class="relative group">What I Captured (this part is mine)
 &lt;div id="what-i-captured-this-part-is-mine" class="anchor">&lt;/div>
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none">
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#what-i-captured-this-part-is-mine" aria-label="Anchor">#&lt;/a>
 &lt;/span>
 
&lt;/h2>
&lt;p>The honeypot that recorded this was &lt;strong>Adbhoney&lt;/strong>, one of T-Pot&amp;rsquo;s sensors that simulates the &lt;strong>ADB (Android Debug Bridge)&lt;/strong> protocol — Android&amp;rsquo;s remote debugging system, which when exposed to the internet without authentication is a trivial entry point for automated bots.&lt;/p></description></item><item><title>I Set Up a Honeypot and I'm Going to Report What I See Every Week</title><link>https://bardlaudian.github.io/honeypot/introduccion/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://bardlaudian.github.io/honeypot/introduccion/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl">
 I&amp;rsquo;m going to intentionally expose a server to the internet so it gets attacked — and then write about it here, every week. No simulations or lab data: real malicious traffic, from the real internet, against a server that does nothing but wait for someone to try to break in.
&lt;/div>

&lt;hr>

&lt;h2 class="relative group">What This Is
 &lt;div id="what-this-is" class="anchor">&lt;/div>
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none">
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#what-this-is" aria-label="Anchor">#&lt;/a>
 &lt;/span>
 
&lt;/h2>
&lt;p>This blog documents what a &lt;strong>honeypot&lt;/strong> — a decoy system designed to look vulnerable and attract attacks — detects in real time, week by week.&lt;/p></description></item></channel></rss>