Honeypot captures
Malware sample inventory
Malware caught on the Kinryū Labs honeypot network, quarantined and hashed. Hashes are printed in full because that is what a defender matches against; attacker infrastructure is defanged. Most families are shared with researchers and defenders who ask. One is mirrored to a public repo that carries a working local-root exploit. Each capture has its own page, and the deep ones link to a full report.
godhive 1
- godhive Novel, not on VTC2 live
4194f2337c2b261e…Exposed Docker API July 15, 2026
Go DDoS botnet 1
- Go DDoS botnet VT 40/74C2 live
6da756970a411dad…Jenkins Script Console RCE July 1, 2026
rootpacket 1
- rootpacket VT 29/74CVE-2026-31431
e2d0dab6b29df89d…Docker API → privileged-container host escape June 15, 2026
kworker 1
- kworker VT 37/74
7420e819e6cf6d76…Exposed Redis (cron injection) June 10, 2026
RedTail 1
- RedTail Known family
59c29436755b0778…Exposed Docker API June 5, 2026
No captures match that filter.
Commodity captures
The network also pulls a steady volume of commodity malware, quarantined and hashed on capture. It gets catalogued and left there; none of it is novel enough to earn a teardown.
- Mirai / Gafgyt variants. Multi-arch ELF drops via Telnet brute-force, the dominant volume. 11–14 architecture binaries per campaign wave.
- Jenkins DDoS droppers. Groovy RCE via the Script Console; a bins.sh loader plus arch-specific ELF/PE payloads. Overlaps with the Go DDoS botnet above.
- ESXi OpenSLP payloads. CVE-2021-21974 exploit attempts over UDP/TCP 427; mostly small protocol payloads.
- Malicious Redis modules. Backdoor / loader .so modules loaded via MODULE LOAD.
Requesting a sample
A few families are mirrored to our public GitHub and link straight there. For the rest, email [email protected] and say who you are and what you need it for. Everything on this page is functional malware, and one repo carries a working local-root exploit, so run any of it in a disposable VM with no route to a network you use.