FLUX FLEET — INTEL BRIEFING №3
Period: 30–31 Aug 2026 (24h, day 3 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; baselines now populated)
Related: Briefings №1–2 (docs/intel/); digest medina:/data/flux-logs/reports/flux-digest-2026-08-31.md
BLUF
Volume escalated sharply on two fronts: the control node absorbed a 24K-event day (+820%) driven by two industrial bursts — a 12,707-path malware-dropper dictionary blast and an 8,300-path/88-family template sweep by Techoff Srv infrastructure — while the AI/dev node took a new 8,146-request WordPress xmlrpc brute-force from Google Cloud. Most significantly, a residential-Netherlands IP executed a full multi-stage attack (NightAgent webshell RCE verification + cPanel root brute + WordPress batch SQL injection) against both EU nodes, marking the first single-IP cross-node campaign and the first residential-source attacker. All four standing campaigns persisted (⟳). Canary mint failures hit zero; 45 more tripwires distributed (fleet total ~140).
Key Judgements
- Cross-node IP reuse has begun — Briefing №1's uniqueness judgement is superseded. Two IPs (a DELTA Fiber residential-NL address and an SS-Net RO scanner) hit multiple nodes with the same journeys. As the fleet's fingerprints propagate (CT logs, scan-feed listings, passive DNS), attacker tooling is beginning to correlate our nodes. Campaign tracking by journey signature remains the right architecture — it caught both reuse cases automatically. (High confidence)
- The control node has entered the heavy-scan population. Day-over-day: 2,052 → 3,186 → 24,100 events (88 IPs, superlinear). Two deliberate bursts (below) plus the day-2 stalker continuing (Pfcloud, day 3 of continuous recon) mean the "fresh IP baseline" is now a contested baseline — differentials should weight per-IP-normalized trap-family distributions, not raw counts. (High confidence)
- Malware-distribution infrastructure is using our node as a staging-check target. The 12,707-path dictionary was a malware-payload URL list (
/1.bat,/0x83911d24Fx.sh,/.tygahhh/ENCRYPTED.ps1— URLhaus-style feed replay), probing for open dirs serving dropped payloads. The control node's fresh IP matched a malware-feed fingerprint. (Moderate-high confidence) - Residential sources are entering the mix — DELTA Fiber NL multi-stage attacker and Office National des Postes (Morocco) IPs. Home-connection proxies (residential proxy networks) would explain single-residential-IP multi-node, multi-campaign behavior. (Moderate confidence)
Active Campaigns (day 3 status)
⚠ NEW: NIGHTAGENT (residential multi-stage intrusion) — hostile, high interest
- Actor: 81.172.241.94 — DELTA Fiber Nederland residential ISP (python-requests + forged Chrome/Firefox UAs)
- TTPs against BOTH EU nodes (same journey, http + https + IP-literal + hostname surfaces, within ~50 min):
- phpunit CVE-2017-9841 POST with
<?php echo "NightAgent";?>verification payload — active webshell implantation testing (NightAgent is a known implant family) - cPanel/WHM login brute (
user=root&pass=wrong, python-requests,?login_only=1) - WordPress batch API SQL injection — nested
wp-json/batch/v1multiplex payload containingauthor_exclude=0) UNION SELECT ... CONCAT(0x7c7c, HEX(...), 0x7c7c)...— blind-SQLi data-exfiltration attempt via post-ordering side channel (flux returned 207 with the batch correctly processed; injection did not execute) - Redirect-chain tarpit engagement at every first-contact
- phpunit CVE-2017-9841 POST with
- Assessment: a single operator (or residential-proxy-routed operator) running a full intrusion chain — recon → RCE verification → credential brute → injection. The highest-sophistication per-request actor observed in the fleet so far, and the first residential one. Watch for return; watch Tracebit for aws canary callbacks from this source
⚠ NEW: XMLRPC-BRUTE (WordPress xmlrpc) — hostile, industrial
- Actor: 34.63.40.186 (Google Cloud, US) — 8,146 POSTs to
/xmlrpc.phpin 31 minutes, plus standard WP discovery (wlwmanifest.xml,wp-json/wp/v2/users/, oembed) - Assessment: classic xmlrpc credential-amplification brute (pingback/user enumeration). AI/dev box's WP surface is being brute-forced by cloud infrastructure
⚠ NEW: MALWARE-DICT (dropper-path dictionary blast) — purpose unclear, bulk
- Actor: 169.150.201.29 (Datacamp/CDN, DE, ipsum-listed) — 12,707 unique paths in ~60 seconds against the control node (05:18–05:19 UTC), zero repeat paths
- TTPs: replay of a malware-distribution URL dictionary (
*.bat,*.exe,*.sh,ENCRYPTED.ps1under random dirs) - Assessment: malware-feed URL verification (checking feed URLs against random hosts — common for feed-quality scoring or CDN-abuse probing). Also possible: open-directory hunting for staged payloads
⟳ REGISTRY-HUNT — day 3, continuing
- 4 fresh IPs per EU node signature (both variants again), byte-identical 12-step journey, 164 events each. Three days, three IP sets, same tooling. Internal Docker-registry enumeration remains the campaign's signature interest
⟳ RCE-SWARM (phpunit/CGI) — day 3, fleet-wide
- 7 IPs across all 3 nodes (343 events) — the swarm has now been running continuously against the fleet for 3 days with rotating infrastructure
⟳ TECHOFF (new standing actor)
- 45.148.10.183 (Techoff Srv Ltd, NL, ipsum:2 + firehol2) — 8,300 events, 88 trap families, 8,262 unique paths in a 20-minute burst against control (01:27–01:47 UTC). Same org as day-2's 45.148.10.238 — Techoff is now a recurring fleet actor with rotating /24 infrastructure running full-template industrial sweeps
Standing actors (persistence check)
- Pfcloud UG (204.76.203.18) — day 3 of continuous low-and-slow control recon (1,994 more events; now 3+ days unbroken)
- SS-Net (80.94.95.211) — hit farm AND aidev (first cross-node IP besides NightAgent actor)
- Office National des Postes (Morocco) — second consecutive day, different IPs from same ASN, both POST-bearing
- 213.209.159.175 (Feo Prest) — returned again (334 events)
- Censys, Palo Alto — benign research cadence unchanged
Fleet Observations
- Canary economics day 3: 45 mints (control 19, farm 15, aidev 11 — control now leads, fitting its fresh-IP discovery role). Mint failures: zero fleet-wide — the aidev
/.env400 burst from day 2 did not recur. Fleet total distributed: ~140 tripwires across 4 types - The XMLRPC flood answered cleanly: 8,146 POSTs handled without error — flux absorbed a brute-force rate that would degrade many real applications, validating the tarpit/capacity design on the AI node
- aidev volume profile shifted: +195% but unique IPs down (413 → 101) — concentration into fewer, bigger automated actors (the xmlrpc flood + GCP sweeps) rather than broad discovery. Different defense problem: rate/behavioral, not breadth
- Fleet totals: 51.6K log lines / 3 days. The wp-batch SQLi payload and NightAgent chain are the first captures of in-payload hostile code (bodyPreview + bodySha256) — payload-hash clustering is now viable for cross-campaign tooling correlation
Gaps / Next Collection
- Tracebit callback watch remains the top collection priority — ~140 tripwires distributed; the NightAgent actor and registry-hunt are the most likely first callbacks (they collect credential files aggressively)
- bodyPreview truncation: the WP-batch SQLi was visible only because it fit the preview window — consider whether flux should log bounded body previews on high-value traps (upstream discussion)
- Digest improvement: flag first cross-node IP reuse automatically (the crossnode GROUP BY query needs a fix — it under-reported; the LIKE-based check found the reuse). Candidate: add a cross-node IP-reuse row to the digest's fleet overview
- Control node's raw-volume differential is degrading under burst load — consider per-IP normalization in the spike detection (planned refinement)