FLUX FLEET — INTEL BRIEFING №20

Period: 2026-09-13 07:33 – 2026-09-14 07:33 UTC (24h digest window, day 19 of operations) Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries) Confidence: High (direct observation; 19-day baseline, every result-tag spike attributed by spot query)

The digest window runs 07:33 UTC 09-13 to 07:33 UTC 09-14. The prior briefing №19 closed at 07:36 UTC 09-13, so this window holds only a 3-minute overlap segment (10 /-only tarpit rows on farm — recounted as new here). All times below are raw log timestamps (UTC; the -04-suffixed flux rows are local wall clock, 4 h behind). The +4 h ingest cast widens SQL windows by 4 hours.

BLUF

The credential funnel moved again: 18 credentials minted by one ai-devbox-1 burst at 17:34:09–21 UTC 09-13 all reached AWS within 6 minutes — 52 of 71 use events from 45.67.211.147 (G-Core Labs) under aws-sdk-go-v2 and one scan burst from 103.26.8.88 (GoMami SG), all denied except sts:GetCallerIdentity. This is the second mint-to-use conversion in fleet history. It is the first with a visible mint collector IP and the largest single-batch use (18 credentials vs №19's 3). A new empty-IP .env census wave hit both EU nodes with a 511-path wordlist (510 shared) and minted once. Two smaller census passes ran on control-1 and ru-edge-1 with wordlists that overlap the 112-path core. METADATA-HUNT's empty-IP variant ran its second day (control 06:19, aidev 17:34–18:55, farm 18:58, netcup 21:47, sponge 11:07), and one new Google-hosted runner worked with its source IP intact — 136.117.52.210, 385 events in 14 seconds, 26 mints, the largest single-IP haul since the fleet began. LIBREDTAIL-KIT ran its sixth window with zero captured POST bodies for the second consecutive cycle.

Key Judgements

  1. The 17:34 aidev burst is the fleet's first fully-traced mint→use chain: mint IP visible, use IPs recorded, latency under 6 minutes. Flux logs carry no clientIp on the 17:34 burst rows (the 17:34:09–18 issued rows are all empty-IP), but Tracebit credential labels pin the batch to 18 distinct mints in 12 seconds. The first AWS call landed at 17:39:50 UTC from 45.67.211.147. A second IP, 103.26.8.88, ran 7 operations at 17:40:18–47. (High confidence on the trace — Tracebit labels and flux rows agree to the second. Moderate on operator identity: two use IPs and an unattributed mint leave resale possible, and 45.67.211.147 appears nowhere in flux logs.)
  2. A new 511-path .env census campaign ran twice on the EU nodes; the wordlist is a 510-of-511 match across both runs and a 510-of-513 overlap with the standing Chrome/126 census family. farm ran it at 02:45 under Chrome/126.0.0.0 and aidev at 06:20–06:42 under the same UA, 514 events each. The empty-IP variant minted 1 on aidev (/.env) and failed 1 on farm. (High confidence on the linkage — identical wordlists and UA. The operator is unknown; every prior Chrome/126 census run traced to standing actors 194.180.49.37 and 91.245.74.31, which did not return.)
  3. 136.117.52.210 is the first named METADATA-HUNT-class runner since №14 to mint 26 credentials in one burst and hold them. The IP (Google LLC) ran 385 events, 262 paths, 33 rotating AI-crawler forgeries, 26 mints plus 5 vite-fs-issued rows, 7 upstream 400s, in one 14-second pass on canary-farm-1 (00:41:14–28). Its wordlist carries the @fs traversal, ssrf-relay-*, __aws_leak_probe-class markers, /mcp tooling probes, and graphql introspection. (High confidence on the facts. No AWS use from any of its 26 credentials had fired by window close — the hoard is hostile-held inventory.)
  4. CURL-SWEEP missed its third consecutive window. Only scattered curl/7.74.0 singles ran this cycle (7-event bursts on aidev 21:36, control 23:36, ru-edge 06:15, farm 05:03 — 1 mint-free /.env wave each) with none of the 07:59–08:55 UTC fleet-wave shape of №18–№19. The daily-schedule read now fails; the template looks retired or dormant. (Moderate confidence — absence across one window after two on-schedule runs; a fourth miss closes the question.)

Active Campaigns (day 19 status)

Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.

⟳ METADATA-HUNT (GCP crawler census, empty-IP escalation) — hostile, fleet-wide

  • Actors: The empty-IP variant ran 5 bursts this window: control-1 06:19–06:26 09-13 (114 events / 112 paths, Chrome/45.0.2454.101, 2 mints — one at 06:19:34, one at 08:50 under an OPR/45 forgery), aidev 17:04–18:55 (748 + 688 events, 5 mints + 27×400), farm 18:58:50–57 (113 not-handled, 19 ssrf-relay-*, 0 mints, 13×400), netcup 21:47–21:48 (618 events in 21 s, 0 mints), sponge 07:07 09-13 (40 marker rows, 0 mints). Named runner with source IP: 136.117.52.210 (Google LLC), farm, 00:41:14–28 09-14, 385 events / 262 paths in 14 s, 26 mints.
  • TTPs: Unchanged GCP/AI-config template: /.env variants, /@fs/proc/self/environ, /@fs/root/.env, /.mcp.json, __aws_leak_probe markers, ssrf-relay-aws-index / ssrf-relay-aws-role-list. UA rotation persists: 465+ forged crawler strings per burst, per-request rotation. The 136.117.52.210 run adds graphql introspection (/graphql, /api/graphql, /v1/graphql, 3 POSTs, 86-byte bodies not captured) and an MCP tools-call POST to /mcp (168 bytes, body not captured), the first named-IP MCP probe of this campaign.
  • Assessment: The campaign now runs two shapes: the empty-IP fleet-wide wave (sourceless, low mint yield) and the named single-runner burst (high mint yield). 136.117.52.210's 26 mints make it the largest single-collector haul since the /46 block's 25-mint batches. The mint failures (upstream 400s) continue to track burst speed, not capability.

⚠ ENV-CENSUS-3 (511-path .env wordlist, empty-IP, Chrome/126 UA) — hostile, new name

  • Actors: Unattributed. farm 02:45:18–49 09-14 (514 events / 511 paths, 0 mints, 1×400) and aidev 06:20–06:42 (514 events / 511 paths, 1 mint at /.env, 0×400). Wordlist overlap between the two runs: 510 of 511 paths. Overlap with the standing Chrome/126 census family (09-04/05/06/08, 743 distinct paths): 510 of 513 — the same wordlist, pruned and re-run.
  • TTPs: The .env-variant directory fanout with webshell-sweep (/index1.php, /test_phpinfo5.php), yii2 debug, sftp-config, and wp-config-backup.php families. Single UA, single pass per node, 31 s on farm, 22 s spread on aidev.
  • Assessment: Third generation of the CREDSWEEP-lineage wordlist. Prior runs attributed to 194.180.49.37 (09-04) and 91.245.74.31 (09-05, 09-06), both of which broke their streaks this window; the operator either retired the named IPs or the template now runs unattributed like OMEGA-SWEEP did after №15. Promotion from ENV-CENSUS-2 lineage is warranted because the empty-IP propagation and the 511-path list are new.

⟳ OMEGA-SWEEP (107-family config census, forged Googlebot/2.1) — hostile, contracted to a single-node return

  • Actors: Unattributed. canary-farm-1 21:18:04–18 09-13: 1,500 events / 1,342 paths / 14 s, 0 mints, 7×400. Stray single events under the same forged UA on sponge (16:22), control (07:14 09-14), and farm (7 rows inside the 136.117.52.210 window).
  • TTPs: The census ran a 1,342-path list — 80% larger than the aidev core of №14 (743 paths) and larger than №19's control run (1,033). Forged Googlebot/2.1 on every row. Result mix holds the 107-family shape: wp-config-error 27, app-config-python-error 25, app-config-php-error 22, fake-git-error 22, webshell-sweep-observed 14, phpmyadmin-login 11.
  • Assessment: Fourth window of expansion, then contraction to one node. The /46 block (94.154.46.x) minted nothing this window — first absence since №16. The 1,342-path list growth says the operator still develops the census even while hiding its source.

⟳ REGISTRY-HUNT (LeakIX weblogic/confluence/docker-registry walk) — borderline scanner, six-IP wave

  • Actors: 6 runners this window, same count as №19: 4 named DigitalOcean runners (209.38.248.17 aidev, 167.71.175.236 aidev, 157.230.19.140 farm, 159.89.12.166 farm) plus 2 empty-IP runners, 39 events per named IP at 20:40–20:43 UTC, 78 events per empty-IP runner. Two UA variants persist (l9scan/2.0.632323… aidev, l9scan/2.0.234313… farm), 156 events per variant.
  • TTPs: Unchanged 12-step walk: tarpit → WebLogic console → server-status → Confluence → WHM/cPanel subdomains → docker-registry /v2/internal/.... Zero mints this window — first time the wave has minted nothing since №16.
  • Assessment: LeakIX stays borderline per registry. The named-runner set is stable across windows (the same 4 IPs recur since 08-29), which reads as a scheduled scanner with a fixed runner pool rather than rotation.

⚠ CREDENTIAL-DRAIN (17:34 mint burst + AWS consumption) — hostile, new

  • Actors: Mint side unattributed (empty-IP rows on aidev 17:34:09–22, forged AI-crawler UAs: Slackbot-LinkExpanding, GPTBot/1.4, OAI-SearchBot/1.4, ChatGPT-User/1.0, Claude-User/1.0). Use side: 45.67.211.147 (G-Core Labs S.A., US) — 70 events, aws-sdk-go-v2/1.46.0; 103.26.8.88 (GoMami Networks, SG) — 7 operations at 17:40:18–47.
  • TTPs: 18 credentials minted at /.env, /app/.env, /config.js, /@fs/root/.aws/credentials, /proc/self/environ, and siblings, then used within 6 minutes. Operation set: sts:GetCallerIdentity 42 (success), DescribeInstances 23, ListBuckets 2, GetAccountSummary 2, ListTopics 1, ListFunctions20150331 1 (all denied, Client.UnauthorizedOperation). The 45.67.211.147 stream ran in repeated Describe→GetCallerIdentity pairs every 10–60 minutes for 11 hours — a polling loop, not a burst.
  • Assessment: Two different egress IPs consuming one mint batch points at a credential loader, not a browser session. The 11-hour cadence says the consumer treats the keys as a renewable feed: mint → enumerate → re-check until the 12-hour TTL. This is the fastest and largest conversion the fleet has traced, and it validates the fleet's deny-first IAM posture as the load-bearing control.

⟳ LIBREDTAIL-KIT (phpunit RCE + dropper) — hostile, sixth window, bodies still missing

  • Actors: Unattributed. 6 runs fleet-wide: aidev 51 events (10:01–02:09), farm 134, control 129, frantech 99, ru-edge 49 (one 1.6-second burst 13:48), sponge 98. 84 POSTs fleet-wide, zero captured bodyPreview.
  • TTPs: Template unchanged: phpunit-eval-stdin probe across 20+ eval-stdin.php paths, then POST /index.php and POST /bin/sh. The digest attributes sponge's phpunit-eval-stdin 75-event spike (infx on a first-full-window baseline) to this kit's 74 events.
  • Assessment: Second consecutive window with no dropper payload captured. Either the condensed feed lost bodyPreview for these rows in both cycles (unlikely — the wp-login bodies captured fine) or the template stopped sending the dropper this week. The staging host remains unmeasured.

⚠ MALWARE-DICT-2 (IoT dropper-URL dictionary replay, dual-node) — hostile, new name

  • Actors: Unattributed. control-1 486 events / 174 paths and ru-edge-1 481 events / 174 paths, byte-identical timing on both nodes (first rows within 0.6 s of each other at 09:12:49 09-13, matching hourly bursts through 06:43 09-14), empty UA on every row.
  • TTPs: The /bins/* and /hiddenbin/boatnet.* dropper families ran the same hourly pass on both fresh-IP nodes: /bins/x86.64, /bot.sh4, /z/mpsl, /0010101010100101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.{spc,arm6,arm7}, /kitty.*, /lol.*, /i-5.8-6.Sakura, /HBTs/top1miku.m68k.
  • Assessment: This is the MALWARE-DICT loop shape (URLhaus-style dictionary replay) with two differences that justify a separate name: it runs synchronized on two nodes, and it runs empty-UA with no /etc-style companion probes. Synchronized timing is stronger evidence of one operator than the №13–№14 Pfcloud loop, which ran on a single node. The wordlist overlap check (174/174 shared paths) pins the campaign identity.

Standing actors (persistence check)

  • 136.117.52.210 (Google LLC) — first-ever appearance, 385 events, 26 mints. Watch: if it returns on any node, the 1:1 mint-to-event ratio pattern (like 40.87.20.23 in №19) makes it a collector signature, not a scanner.
  • 40.87.20.23 (Azure) — returned on schedule at the window edge: farm /.env mint at 07:10:41 09-13, its 2nd all-time event, 2nd mint. The 1:1 events-to-mints ratio across two nodes now holds for both its appearances.
  • Absent: 176.65.148.71 (broke a 6-visit streak), 194.180.49.37 and 91.245.74.31 (the Chrome/126 census pair — the census template ran unattributed instead), 80.94.95.211 (2nd absent window), 45.148.10.238, 91.245.74.31, 213.209.159.x, 204.76.203.x (MALWARE-DICT original loop silent), 43.228.157.68, 193.24.123.123, 35.245.185.138 (the №19 use IP), 136.70.175.146 (the №18 named runner, 3rd idle), the 94.154.46.x block entirely, and 159.26.110.179 (the №14 GetCallerIdentity actor).
  • NIGHTAGENT — third consecutive idle window. Zero NightAgent markers, zero GitHub dropper fetches.
  • XMLRPC-BRUTE — third consecutive silent window (3 stray /xmlrpc.php GETs on aidev, no POSTs).
  • frantech Chrome/114 crawler — 469 events / 469 paths across the window (03:50–04:44), a standing single-node census that №19 sized at 349 paths. Slow growth, same shape.

Canary credentials

Summary

53 Tracebit alert(s) fired in the window (71 use events across 18 credentials). Fleet sensors minted 37 credentials to 1 collector IPs; 18 credential(s) reached AWS. Use outcomes: 42 success, 29 failure. Denied operations: DescribeInstances×23, ListBuckets×2, GetAccountSummary×2, ListTopics×1, ListFunctions20150331×1. 42 call(s) succeeded: GetCallerIdentity. Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 37
Distinct collector IPs 1
Credentials used in AWS (alerts) 18
Credentials stolen, no observed AWS use in window 19

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
136.117.52.210 canary-farm-1 26 0 0 26 mints since 2026-09-14 00:41
unknown (outside flux window) 0 18 2 DescribeInstances, GetAccountSummary, GetCallerIdentity, ListBuckets, ListFunctions20150331, ListTopics no flux mints in history window

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • None: 32 mints, 2026-09-12 08:14 → 2026-09-14 06:30
  • 136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:41
  • 136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:55
  • 34.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:26
  • 34.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:44
  • 34.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:09
  • 34.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:10
  • 35.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52
  • 167.99.79.44: 12 mints, 2026-09-08 19:11 → 2026-09-11 18:19
  • 94.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:48
  • 94.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:25
  • 94.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:13
  • 94.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:51
  • 80.94.95.211: 6 mints, 2026-09-07 21:08 → 2026-09-12 02:32
  • 102.220.161.87: 4 mints, 2026-09-07 23:07 → 2026-09-09 13:44
  • 136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33
  • 142.93.129.190: 4 mints, 2026-09-07 20:16 → 2026-09-10 20:23
  • 160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43
  • 176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:56
  • 41.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:45

Canary-use attribution (briefing prose)

All 18 used credentials came from one 12-second mint burst on ai-devbox-1 at 17:34:09–21 UTC 09-13. The flux-side rows for that burst are empty-IP (5 issued rows visible, 27 upstream 400s); Tracebit's credential labels pin all 18 mints to that burst regardless of what the flux feed logged. The consumer opened with DescribeInstances at 17:39:50 — 5 minutes 41 seconds after the first mint. One credential then ran a second scan from 103.26.8.88 at 17:40:18: GetCallerIdentity success followed by GetAccountSummary×2, DescribeInstances, ListBuckets×2, ListFunctions20150331, ListTopics, all denied. The rest of the batch stayed on 45.67.211.147 in a Describe→GetCallerIdentity polling loop that ran to 04:47 UTC 09-14, inside every credential's 12-hour TTL.

The use IP 45.67.211.147 (G-Core Labs, an-announced-us Manassas block) appears nowhere in flux logs, all-time or window — same pattern as №19's 35.245.185.138. G-Core is a CDN/anycast provider, so the IP may be a rotating egress, not a fixed host. The two-IP split (one steady consumer, one burst enumerator) matches an automated credential-vetting tool rather than a human session: load the key, run GetCallerIdentity, attempt the inventory calls the deny policy blocks, record, move to the next key. What remains unproven: whether 45.67.211.147 is the same party that scraped the trap, or a downstream consumer of a resale chain. The 5-minute latency makes resale unlikely but does not exclude an automated handoff.

The None collector row (32 mints, 09-12 08:14 → 09-14 06:30) carries the empty-IP batches: the METADATA-HUNT waves, the Chrome/126 census mint, and the control-1 and ru-edge singles. 136.117.52.210's 26 mints show as unused in this window's Tracebit pull — the mint→use check for its TTL window (expires by 12:41 UTC 09-14) is the first item for the next cycle.

Fleet Observations

  • Canary economics: 39 mint rows to 5 named/collectable IPs (digest: aidev 6, farm 30, control 2, ru-edge 1); 75 upstream 400 failures (aidev 27, farm 33, control 14, ru-edge 1). Failure ratio 1.9:1, down from №19's 3.6:1. All mints aws-type. The digest's 39 counts raw issued rows; the Tracebit section's 37 counts distinct credentials — the difference is mint rows the flux feed logged with non-issued results (the 17:34 burst logged /config.js as webapp-config-bundle-js while Tracebit minted it).
  • XFF forgery: 646 requests carried an X-Forwarded-For header; 0 multi-entry chains, 0 all-internal 127.0.0.1 rows — the fleet-side fix held for a tenth window.
  • Attribution gap widened: 13,933 of 15,047 window rows (92.6%) carry an empty clientIp — 100% on all five no-canary/certless nodes, 95.0% on aidev, 88.2% on farm. Every campaign in this briefing except REGISTRY-HUNT's 4 named runners and the wp-login brute pool ran unattributed. The socket-peer fix (ops repo, carried since №17) remains the highest-value change available.
  • Control discovery velocity: day 19 cell: 3,152 events, 0 attributable IPs (digest shows 1 uniq = the NULL group). The node logged +3% events over baseline on an all-empty-IP feed. Ramp series for the record: 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 → blind → blind → blind → 51 (4 h) → 52 → 0 real.
  • TLS/attribution posture: farm 511 https events (598 Host-header hits on sso.rightabouteverything.show), aidev 132 https on inference.fapthropic.com, the five certless nodes 0. Commodity IoT probes (/boaform, TP-Link diag) absent this window after their №19 first appearance.
  • Result-tag spikes: all attributed. farm's 33× wp-config-error and 30× app-config-php-error are the OMEGA 21:18 census; the 5× env-production-error/app-config-*-error clusters on farm are the METADATA-HUNT 18:58 burst and the Chrome/126 census; ru-edge not-handled 12.6× is the MALWARE-DICT-2 dictionary (611 distinct paths, most of them one-off dropper URLs); sponge phpunit-eval-stdin infx is LIBREDTAIL's first sponge run; frantech/netcup/ru-edge infx ratios are first-full-window baselines for the new nodes.
  • Mint-label quirk (new): Tracebit mints can carry flux results other than issued when the trap's 200-family result classification wins. The 17:34 /config.js mint row logged webapp-config-bundle-js. Digest mint totals therefore undercount by however many mint rows fell into 200-family result labels; count credential batches from Tracebit labels, not flux results, when the two disagree.

SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)

  • New commands: zero. All 56 distinct commands this window were seen before. The 1,720-event uname -s -v -n -r -m pair (2 IPs) and the 108-IP rm -rf .ssh + authorized-keys inject remain the load-bearing recurring set.
  • Funnel: 334 sources sent credentials → 237 got a shell (71%) → 148 ran a command (62% of shell-getters, 44% of sources). Event level: 25,510 attempts → 14,660 accepted logins → 7,000 commands (48% of accepted logins run something). The per-login conversion held from №19.
  • Credentials: 9,267 distinct pairs, 0 new. Concentration is the signal: the 345gs5662d34/3245gs5662d34 family owns the top 5 rows (2,282 attempts across 4 usernames) — a single wordlist family, commodity noise.

Gaps / Next Collection

  1. 136.117.52.210's 26-credential TTL window. The batch minted 00:41 UTC 09-14; TTL expires by 12:41. Pull Tracebit alerts for 09-14 00:41–13:00 at the next cycle's start — any AWS call from that batch ties the named METADATA-HUNT runner to a consumer for the first time with the mint IP on record.
  2. 45.67.211.147 follow-through. The Describe→GetCallerIdentity loop ended 04:47 UTC. Pull the CloudTrail set for the 18 credentials' full TTLs — a second consumer IP or any post-TTL callback extends the chain. 103.26.8.88 (GoMami SG) ran 7 operations once; treat as a different stage of the same pipeline until it returns.
  3. LIBREDTAIL dropper capture, second pass. Two consecutive windows with zero POST bodies across 84 POSTs. Next cycle, check the raw node-side flux logs directly (before the condensed feed) for one run — if bodies exist there, the digest feed is the loss point; if not, the template dropped its payload stage.
  4. ENV-CENSUS-3 recurrence. The 511-path list ran twice in 4 hours. If a third run lands on control-1 or a no-canary node, the campaign is fleet-wide automation; watch for the named IPs (194.180.49.37, 91.245.74.31) to return and re-claim it.
  5. Socket-peer logging for headerless requests (carried from №17–№19). 92.6% of this window's rows are unattributed. Four campaigns (METADATA-HUNT empty-IP wave, ENV-CENSUS-3, CURL-SWEEP, MALWARE-DICT-2) attribute at once if it ships. No fleet-side action from this workflow.
  6. CURL-SWEEP retirement call. Third consecutive miss. One more silent window and the registry entry moves to standing-paused.

Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-14.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (136.117.52.210), plus 28 ad-hoc v_full queries (METADATA-HUNT marker distribution, Chrome/126 census linkage and wordlist-overlap matrix, OMEGA-SWEEP farm return, MALWARE-DICT-2 dual-node timing, REGISTRY-HUNT named-runner history, wp-login pair census, standing-actor persistence batch, empty-IP share per sensor, tracebit-http-error mint attribution, config.js mint-label quirk) and the Tracebit canary-section generator plus a per-alert tracebit-alerts logs pull (53 alerts, 71 use events).