Honeypot captures

Malware sample inventory

Malware caught on the Kinryū Labs honeypot network, quarantined and hashed. Hashes are printed in full because that is what a defender matches against; attacker infrastructure is defanged. Most families are shared with researchers and defenders who ask. One is mirrored to a public repo that carries a working local-root exploit. Each capture has its own page, and the deep ones link to a full report.

Write-ups
20
11 families
With full teardown
5
linked report
Captures
828
345 distinct SHA-256
Novel (VT = 0)
130+
incl. the godhive framework
Delivery vectors
8
Docker, Jenkins, Redis…

mozi 3

unclassified 7

redtail 1

  • redtail C2 verified 7c6c19b6e9343c77… Runs as a dropper/loader; the entry vector is not established by static analysis September 20, 2026

nsminer 1

mirai 2

atomic-mirai 1

  • atomic-mirai C2 recovered 42f1363b224766f6… Runs as a loader/dropper; the entry vector is not established by static analysis September 7, 2026

godhive 1

Go DDoS botnet 1

rootpacket 1

kworker 1

RedTail 1

Commodity captures

The network also pulls a steady volume of commodity malware, quarantined and hashed on capture. It gets catalogued and left there; none of it is novel enough to earn a teardown.

Requesting a sample

A few families are mirrored to our public GitHub and link straight there. For the rest, email security@kinryu.sh and say who you are and what you need it for. Everything on this page is functional malware, and one repo carries a working local-root exploit, so run any of it in a disposable VM with no route to a network you use.