<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Botnet on Corvus Blog</title><link>https://nicoleman0.github.io/blog-site/tags/botnet/</link><description>Recent content in Botnet on Corvus Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 02 Feb 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://nicoleman0.github.io/blog-site/tags/botnet/index.xml" rel="self" type="application/rss+xml"/><item><title>RedTail 2026 Cryptomining Botnet Campaign</title><link>https://nicoleman0.github.io/blog-site/posts/campaign_1/</link><pubDate>Mon, 02 Feb 2026 00:00:00 +0000</pubDate><guid>https://nicoleman0.github.io/blog-site/posts/campaign_1/</guid><description>&lt;h2 id="background">Background&lt;/h2>
&lt;p>I set my ICS/SCADA honeypot (Conpot) up mainly to try and analyze/monitor attacks on industrial systems (this one poses as a PLC for an HVAC system), however the majority of the attempts I&amp;rsquo;ve noticed have been opportunistic web-based attacks targeting the associated page on port 80.&lt;/p>
&lt;p>Recently, I&amp;rsquo;ve noticed some similar looking attacks coming from Asia, both trying to connect to a C2 server.&lt;/p>
&lt;h2 id="log-analysis">Log Analysis&lt;/h2>
&lt;p>Here is an example of one of the logs I captured:&lt;/p></description></item></channel></rss>