Honeypot captures
Malware sample inventory
Malware caught on the Kinryū Labs honeypot network, quarantined and hashed. Hashes are printed in full because that is what a defender matches against; attacker infrastructure is defanged. Most families are shared with researchers and defenders who ask. One is mirrored to a public repo that carries a working local-root exploit. Each capture has its own page, and the deep ones link to a full report.
mozi 3
- mozi (botv2) C2 verifiedProtocol documented
12013662c71da69d…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 30, 2026 - mozi C2 verifiedProtocol documented
f6c97b1e2ed02578…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 13, 2026 - mozi C2 verifiedProtocol documented
4293c1d8574dc87c…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 9, 2026
unclassified 7
- Mips ELF 32-bit MSB executable ddos-bot (9200aac4a356) C2 verifiedProtocol documented
9200aac4a3561902…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 30, 2026 - Arm ELF 32-bit LSB executable ddos-bot (9e6da804ae9c) C2 verifiedProtocol documented
9e6da804ae9ca0a0…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 29, 2026 - Arm ELF 32-bit LSB executable ddos-bot (34186fba4b5a) C2 verifiedProtocol documented
34186fba4b5a9c64…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 28, 2026 - X86_64 ELF 64-bit LSB pie executable ddos-bot (3261921456e3) C2 verifiedProtocol documented
3261921456e347fb…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 27, 2026 - X86_64 ELF 64-bit LSB pie executable ddos-bot (7d7210719451) C2 verifiedProtocol documented
7d7210719451068d…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 27, 2026 - X86 ELF 32-bit LSB executable ddos-bot (59bdafde8769) C2 verifiedProtocol documented
59bdafde87693987…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 22, 2026 - POSIX shell script loader (42f1363b2247) C2 recovered
42f1363b224766f6…Runs as a loader/dropper; the entry vector is not established by static analysis September 20, 2026
redtail 1
- redtail C2 verified
7c6c19b6e9343c77…Runs as a dropper/loader; the entry vector is not established by static analysis September 20, 2026
nsminer 1
- nsminer C2 recoveredProtocol documented
7126b9932dc0cdfe…Runs as a cryptominer/dropper; the entry vector is not established by static analysis September 18, 2026
mirai 2
- mirai C2 verifiedProtocol documented
d8712c619b951fc2…Runs as a ddos-bot; the entry vector is not established by static analysis September 14, 2026 - mirai (pboc) C2 verifiedProtocol documented
c9727a1237b59d53…Runs as a ddos-bot/worm; the entry vector is not established by static analysis September 10, 2026
atomic-mirai 1
- atomic-mirai C2 recovered
42f1363b224766f6…Runs as a loader/dropper; the entry vector is not established by static analysis September 7, 2026
godhive 1
- godhive Novel, not on VTC2 live
4194f2337c2b261e…Exposed Docker API July 15, 2026
Go DDoS botnet 1
- Go DDoS botnet VT 40/74C2 live
6da756970a411dad…Jenkins Script Console RCE July 1, 2026
rootpacket 1
- rootpacket VT 29/74CVE-2026-31431
e2d0dab6b29df89d…Docker API → privileged-container host escape June 15, 2026
kworker 1
- kworker VT 37/74
7420e819e6cf6d76…Exposed Redis (cron injection) June 10, 2026
RedTail 1
- RedTail Known family
59c29436755b0778…Exposed Docker API June 5, 2026
No captures match that filter.
Commodity captures
The network also pulls a steady volume of commodity malware, quarantined and hashed on capture. It gets catalogued and left there; none of it is novel enough to earn a teardown.
- Mirai / Gafgyt variants. Multi-arch ELF drops via Telnet brute-force, the dominant volume. 11–14 architecture binaries per campaign wave.
- Jenkins DDoS droppers. Groovy RCE via the Script Console; a bins.sh loader plus arch-specific ELF/PE payloads. Overlaps with the Go DDoS botnet above.
- ESXi OpenSLP payloads. CVE-2021-21974 exploit attempts over UDP/TCP 427; mostly small protocol payloads.
- Malicious Redis modules. Backdoor / loader .so modules loaded via MODULE LOAD.
Requesting a sample
A few families are mirrored to our public GitHub and link straight there. For the rest, email security@kinryu.sh and say who you are and what you need it for. Everything on this page is functional malware, and one repo carries a working local-root exploit, so run any of it in a disposable VM with no route to a network you use.