Sample inventory

Malware sample inventory

Samples captured on the Kinryū Labs honeypot network. Indicators are defanged and hashes are shown in full for detection. Samples are shared with researchers and defenders on request; working exploits are gated and shared by request only. Full analysis for each family lives in its report.

Captures
828
345 distinct SHA-256
Novel (VT = 0)
130+
incl. the godhive framework
Families
29
across the corpus
Delivery vectors
8
Docker, Jenkins, Redis…
Public reports
6
full teardowns

Deep-analysed families

godhive Novel — not on VTC2 live Exposed Docker API

Purpose-built Rust framework. A multi-chain wallet drainer and exchange-withdrawal automation come first, with XMRig mining as the fallback, plus a worm and a command channel layered to survive takedown. The binary carries strings for far more; the report separates what was observed from what is only scaffolded.

First seen
July 2026
Format
6.2 MB x86-64 ELF (static musl), Rust
SHA-256
4194f2337c2b261ed6e1fd0b6d18f0ba75388bdc91a2658eb827a154ed784f36
VirusTotal
Not on VirusTotal (fully novel)
Report
A novel Rust crypto-stealer and miner framework
Sample
By request — email [email protected]
rootpacket VT 29/74CVE-2026-31431 Docker API → privileged-container host escape

A cryptojacking toolkit with an intel_uncore_freq_aux LKM rootkit that fakes CPU and memory and rebuilds through DKMS, a UPX-packed XMRig, and a rival-killer. It escalates with getroot, a working exploit for CVE-2026-31431 (an AF_ALG page-cache LPE that also escapes containers to the host).

First seen
June 2026
Format
~5 MB toolkit archive (Linux)
SHA-256
e2d0dab6b29df89d123fe8581047a03ac9b89ae8fa0d1f334b5aefbb93152857
VirusTotal
29 engines — trojan.abtrojan/gen2
Report
A Linux cryptojacking toolkit that hides in the kernel
Sample
GitHub repo

The repo includes getroot, the working CVE-2026-31431 LPE (SHA-256 dda96d8a4bcc39dc7679347a4386bf1024152d2ccc46d333725ad0cda855d952). Detonate only in an isolated, disposable VM with no network path to anything you value.

kworker VT 37/74 Exposed Redis (cron injection)

A Redis cron-injection dropper that kills 80-plus rival miners, uninstalls Alibaba and Tencent cloud-security agents with the vendors’ own tools, trojanises ps/top/pstree to hide its XMRig, backdoors SSH, and worms onward. The stage-2 miner (javae) was never recovered; the C2 did not serve it at fetch time.

First seen
June 2026
Format
36 KB POSIX shell script (636 lines)
SHA-256
7420e819e6cf6d7608e475468ae0160185fe7eed0b5b4129aad3e8dabc776e30
VirusTotal
37 engines — trojan.shell, 8220/kworkerds lineage
Report
The cryptominer that brings its own uninstaller
Sample
By request — email [email protected]
Go DDoS botnet VT 40/74C2 live Jenkins Script Console RCE

A Go-compiled DDoS botnet-for-hire distributed as a multi-architecture dropper suite. Fifteen attack methods, IoT scanner exploits, SSH spreading, and layered persistence, fronting a self-serve, account-gated DDoS-for-hire API.

First seen
June–July 2026
Format
6.25 MB PE32+ x86-64 + multi-arch ELF variants (Go)
SHA-256
6da756970a411dade9db3c921ef4cdade550f317703d0fc12090a15d8c6778d4
VirusTotal
40 engines — trojan.gorat/flooder; three distinct builds captured
Report
A cross-platform Go DDoS botnet-for-hire
Inside a gaming DDoS-for-hire operation
Sample
By request — email [email protected]
RedTail Known family Exposed Docker API

An XMRig-based Monero miner that runs fileless via memfd_create, ships an embedded SSH client and a libpcap sniffer, and self-replicates by dropping an SSH key. This is a current, fully captured instance of RedTail delivered through an exposed Docker API.

First seen
June 2026
Format
~1.88 MB, multi-arch (x86_64 / i686 / aarch64 / arm7)
SHA-256
59c29436755b0778e968d49feeae20ed65f5fa5e35f9f7965b8ed93420db91e5
VirusTotal
Known family (active since late 2023); encrypted config, no embedded wallet
Report
Self-propagation through exposed Docker APIs
Sample
By request — email [email protected]

Commodity captures

Alongside the deep analyses, the network pulls a steady volume of commodity malware, quarantined and hashed. These are catalogued rather than written up individually.

Requesting a sample

Some families are mirrored to our public GitHub and link there directly; the rest are shared with researchers and defenders by request. Everything here is captured, functional malware, and one repo carries a working local-root exploit, so handle any of it only in an isolated, disposable VM with no network path to anything you value. For a by-request sample, email [email protected] with who you are and what you need it for.