Honeypot captures

Malware sample inventory

Malware caught on the Kinryū Labs honeypot network, quarantined and hashed. Hashes are printed in full because that is what a defender matches against; attacker infrastructure is defanged. Most families are shared with researchers and defenders who ask. One is mirrored to a public repo that carries a working local-root exploit. Each capture has its own page, and the deep ones link to a full report.

Write-ups
5
5 families
With full teardown
5
linked report
Captures
828
345 distinct SHA-256
Novel (VT = 0)
130+
incl. the godhive framework
Delivery vectors
8
Docker, Jenkins, Redis…

godhive 1

Go DDoS botnet 1

rootpacket 1

kworker 1

RedTail 1

Commodity captures

The network also pulls a steady volume of commodity malware, quarantined and hashed on capture. It gets catalogued and left there; none of it is novel enough to earn a teardown.

Requesting a sample

A few families are mirrored to our public GitHub and link straight there. For the rest, email [email protected] and say who you are and what you need it for. Everything on this page is functional malware, and one repo carries a working local-root exploit, so run any of it in a disposable VM with no route to a network you use.