FLUX FLEET — INTEL BRIEFING №21
Period: 2026-09-14 07:34 – 2026-09-15 07:34 UTC (24h digest window, day 20 of operations)
Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation, 20-day baseline, every result-tag spike attributed by spot query)
The digest window runs 07:34 UTC 09-14 to 07:34 UTC 09-15. The prior briefing №20 closed at 07:33 UTC 09-14, so this window holds a 1-minute overlap only. All times below are true UTC from the raw
timestampstrings. The fleet-24h histogram labels its buckets in EDT (UTC−4). Each bucket's true UTC time is label + 4 h.
BLUF
The fleet logged 19,639 events in 24 hours, and two fleet-wide census machines owned the volume. OMEGA-SWEEP returned fleet-wide for the first time since №16: forged Googlebot/2.1 censuses hit 6 of 7 nodes, with the largest runs at 1,584 events on ru-edge-1 and 1,050 on control-1. METADATA-HUNT's empty-IP wave ran twice — 811 events on ai-devbox-1 at 21:59 09-14 and 814 on ru-edge-1 at 06:00 09-15 — with 630 of 631 paths shared. Credential activity stayed low: 7 mint rows, 81 upstream rejections, zero AWS use. The mint→use funnel stayed closed for a third window. frantech-ts produced its first full flux window with 2,671 events, and its ssh/telnet honeypot saw the first password-change loops of the observation period. No new canary credentials reached AWS.
Key Judgements
- OMEGA-SWEEP returned at fleet scale with a grown wordlist, but the /46 block stayed silent for a second window. The forged
Googlebot/2.1census ran on 6 nodes in this window: control-1 986 paths at 22:37–22:59 09-14 and 1,042 paths at 03:21–03:21 09-15, ru-edge-1 1,584 paths at 02:15–02:15 09-15, ai-devbox-1 556 paths at 15:02–15:03 09-14, frantech-ts 150-path passes at 12:36, 20:15, 04:46, 08:27 UTC plus a 207-path expansion, and netcup-ts 150 paths at 10:xx 09-15. The wordlist grew from the №14 core of 743: the ru-edge run is a strict superset of the aidev 556-path list, and frantech's 207-path list adds 57 Aliyun/Qcloud credential paths (/.aliyun/credentials.*,/qcloud.txt,/cos.yaml) that the ru-edge list lacks. (High confidence on the census identity — byte-identical 150-path core across frantech, netcup, and ru-edge passes. Moderate on operator: the /46 block produced only 2tracebit-http-errorrows (94.154.43.164, 94.154.43.146), so the template still runs unattributed on the empty-IP nodes.) - METADATA-HUNT's empty-IP wave now runs a 631–633-path wordlist with 13
/.envupstream rejections per burst, and minted nothing. Two bursts in the window match the campaign's fingerprint: 434 forged crawler UAs on aidev and 450 on ru-edge-1, with identicalssrf-relay-aws-index/ssrf-relay-aws-role-list,firebase-json, andaws-credentials-fileresult mixes, and 630 shared paths between the two runs. Every mint attempt inside both bursts failed with upstreamBad Request. (High confidence on attribution — the UA-rotation density and the@fs/__aws_leak_probemarker set are unique to this campaign. The wordlist grew from ~600 paths in №19–№20 to 631–633, so the operator still maintains it.) - CURL-SWEEP missed its fourth consecutive window and moves to standing-paused. The
curl/7.74.0-era fleet wave never appeared. The curl-family events this window arecurl/8.5.0inside the named-IP.envwalkers andcurl/7.68.0inside the new 404-path census — different tools, different schedules. (High confidence: the №18–№19 wave shape at 07:59–08:55 UTC appeared on no node.) - The mint→use funnel closed for the third window, and the standing hoard grew to 37 credentials with zero observed use. Tracebit recorded no AWS use in the window. The
Nonecollector row (empty-IP mints) grew to 37 over the trailing 6 days. The 136.117.52.210 batch of 26 credentials from №20 expired unused — its TTL window closed at 12:41 UTC 09-14 with no callback. (High confidence on the zero-use observation. The pull window covers the full TTL.)
Active Campaigns (day 20 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
⟳ OMEGA-SWEEP (forged Googlebot/2.1 config census) — hostile, fleet-wide return, wordlist growing
- Actors: Unattributed (empty
clientIpon every row). Run map: control-1 22:37–22:59 09-14 (986 paths) and 03:21–03:21 09-15 (1,042 paths, 16 s), ru-edge-1 02:15:05–23 09-15 (1,584 paths, 18 s), ai-devbox-1 15:02–15:03 09-14 (556 paths, 11 s). frantech-ts ran 150-path passes twice each at 12:36 09-14, 20:15 09-14, 04:46 09-15, and 08:27 09-15, plus a 207-path run at 08:47 09-15. netcup-ts ran 150 paths at 10:xx 09-15. The 09-15 09:00 control hour held a third census variant (457 paths under 9 rotating UAs, 09:28:04–46). - TTPs: Unchanged 107-family template with two changes. The wordlist grew: the ru-edge 1,584-path list strictly contains the aidev 556-path list, and frantech's 08:47 run carries 57 Aliyun/Qcloud-family credential paths absent from every other node's list (
/.aliyun/credentials.env,/qcloud.json,/cos.yaml,/config/tencent.php,/api_keys.*). The campaign's old 150-path short list still circulates unchanged on the deception-only nodes — 6 byte-identical passes. Mint outcome: 5 upstream rejections in the 22:00 control burst, 7 in the 03:00 burst, 6 in the ru-edge 02:15 burst. - Assessment: Fourth census-generation step since №14 (743 → 1,342 → 1,041 → 1,584). The Aliyun/Qcloud addition says the operator extends the template toward Chinese-cloud credential stores. The fleet holds: fake-credential 200-family responses mint nothing from these sweeps because they hit non-trap paths, and every
/.envinside the census attempts minted and failed. Watch for the /46 block to return and re-claim the named-IP role.
⟳ METADATA-HUNT (empty-IP AI-crawler census, 631–633 paths) — hostile, two large bursts
- Actors: Unattributed. aidev 21:59:08–45 09-14 (811 events, 631 paths, 434 forged UAs) and ru-edge-1 06:00:05–45 09-15 (814 events, 633 paths, 450 forged UAs). Smaller marker passes ran on farm (10 rows), control, sponge, netcup, frantech (6 rows each, 1 s each).
- TTPs: Template unchanged:
/.envfanout,@fsVite traversal (70 rows in the aidev burst),__aws_leak_probe,ssrf-relay-aws-index/-role-list(38 rows each burst),/mcpand graphql probes, and forged AI-crawler UA rotation (Slackbot-LinkExpanding, GPTBot/1.4, OAI-SearchBot/1.4, ChatGPT-User/1.0, Amzn-SearchBot, PerplexityBot). Mint attempts: 13 upstreamBad Requestrejections per burst, all at/.env(aidev 21:59; ru-edge 06:00:25–35). - Assessment: The campaign holds its shape — sourceless, fast, high UA rotation — and keeps a maintained wordlist. The 13-mints-attempted-and-failed pattern per burst matches the upstream-rejection behavior №17 documented: rejected batches under burst speed. The two bursts 8 hours apart on different nodes with 630/631 shared paths is one tooling campaign, not two.
⚠ ENV-CENSUS-4 (59-path Chrome/126.0.0.0 short census, 7-node stagger) — hostile, new name
- Actors: Unattributed (empty
clientIp, single IP per node). Sequential pass: aidev 12:31:16–22, farm 13:23:34–45, frantech 13:24:30–37, sponge 13:47:17–24, netcup 14:08:06–12, ru-edge 14:52:05–11, control 14:55:31–40 09-14 — 68 events and 59 paths per node, ~2 h 24 min end-to-end. - TTPs: One UA on every row:
Chrome/126.0.0.0exact string. The 59-path list targets credential files, OpenAPI/Swagger surfaces, actuator endpoints, and Laravel Telescope assets, and carries two garbage-fingerprint paths (/8dafe337ad7c41223b6f31c08f69e36b5972931b,/IE=edge,/width=device-width, initial-scale=1) that mark an automated browser-emulation run. Only 13 of 59 paths overlap the 511-path ENV-CENSUS-3 list that ran the same morning on aidev (10:20:26–10:42:18, 511 paths, 1 mint at/.env). - Assessment: The Chrome/126 string is the ENV-CENSUS-3 lineage's UA, but this is a different, much shorter list that hit all 7 nodes in one coordinated pass — the first full-fleet census wave since CURL-SWEEP went dormant. The stagger pattern (30–40 min between nodes) differs from ENV-CENSUS-3's twin 31 s/22 s runs. Registered as a separate campaign until a shared wordlist proves the link.
⟳ REGISTRY-HUNT (LeakIX l9scan walk) — borderline scanner, reduced footprint
- Actors: 4 named DigitalOcean runners plus 2 empty-IP runners on the EU nodes at 00:05–00:38 09-15: 207.154.212.47 and 68.183.180.73 (aidev), 142.93.143.8 and 143.110.217.244 (farm), 156 events per UA variant (
l9scan/2.0.632323…aidev,l9scan/2.0.234313…farm). control-1 logged 2 stray l9 rows at 23:05 09-14 (l9explore/1.2.2,l9tcpid/v1.1.0) — first appearance on that node. - TTPs: Unchanged 12-step walk (tarpit → WebLogic → server-status → Confluence → WHM/cPanel → docker-registry). 5 upstream mint rejections this window (1 per named IP plus 2 per empty-IP runner) — first mint attempts since №16's 7-mint wave.
- Assessment: The named-runner set holds since 08-29. The behavior is a scheduled scanner. The mint attempts are borderline, not criminal. control-1's first stray rows say the pool probes fresh nodes as they come online.
⚠ ALIYUN-PROBE (rotating-9-UA 404-path census, single-pass) — hostile, new
- Actors: Unattributed (empty
clientIp). Three byte-identical passes in 5 h 58 min: aidev 03:30:13–54 09-15, frantech 08:47:05–49 09-15, control 09:28:04–46 09-15 — 539, 538, and 539 events, 404 paths, 9 rotating UAs per pass (python-requests/2.28.0,curl/7.68.0,Googlebot/2.1bare and forged, Chrome/120, Firefox/121, Firefox/134). - TTPs: Extension-suffix fanout on config-file stems (
/.git/config.{bak,js,json,old,php},/.github/workflows/deploy.{conf,json,txt,yml},/.gitlab-ci.{env,json,yaml}) plus a 21-path/.aliyun/*credential sweep. Zero mints, zero upstream rejections. The firstpython-requests/2.28.0rows in fleet history land in these passes. - Assessment: One template, three nodes, 6 h 18 min apart — a coordinated fleet probe with a wordlist that exists nowhere in prior digests. The Aliyun focus plus the extension-fanout grammar suggests a Chinese-cloud-focused credential collector. Watch for the fourth node.
⟳ ENV-CENSUS-3 (511-path .env census, empty-IP, Chrome/126) — hostile, single return
- Actors: Unattributed. One run this window: aidev 10:20:26–10:42:18 09-14, 511 paths, 1 mint at
/.env(10:20:26). The №20 pair (farm 02:45, aidev 06:20) sat inside the 1-minute window overlap. - TTPs: Same 511-path list and same UA, but the run spread across 22 minutes. №20's passes ran in 31 s and 22 s. 1 mint, 0 upstream rejections.
- Assessment: The wordlist persists and the pacing changed. The slower spread looks like rate-limit avoidance after the №17–№19 rejection streak. The named-IP operators (194.180.49.37, 91.245.74.31) stayed absent for a second window.
⟳ MALWARE-DICT-2 (synchronized IoT dropper dictionary) — hostile, wordlist expanded
- Actors: Unattributed (empty UA, empty
clientIp). Control-1 643 events / 208 paths, ru-edge-1 638 events / 209 paths, 207 paths shared, hourly bursts with near-identical timing on both nodes through the window (07:37 09-14 to 10:22 09-15). - TTPs: The dictionary grew from №20's 174 paths: two new families appeared —
/huhu/titanjr.*(16 architectures) and/bins/sora.*(14 architectures), 30 new paths, first seen 09-13. Hourly cadence unchanged. - Assessment: The synchronized dual-node loop continues and the operator still maintains the feed. Wordlist growth (174 → 207) tracks the campaign's №20 pattern. The Pfcloud MALWARE-DICT single-node loop stayed silent.
⟳ LIBREDTAIL-KIT (phpunit RCE chain) — hostile, seventh window, bodies still missing
- Actors: Unattributed,
libredtail-httpUA on every row. 6 runs: sponge 198 events (08:19 09-14 to 01:57 09-15, 30 POSTs), frantech 102, control 96, farm 49, aidev 46, ru-edge 2 (2 POSTs at 16:10 09-14). 84 eval-stdin probes, 27POST /bin/sh. - TTPs: Template unchanged:
md5("Hello PHPUnit")probe across ~44eval-stdin.phppaths, thenPOST /index.phpandPOST /bin/shwith 111–1,189-byte bodies. - Assessment: Third consecutive window with zero captured
bodyPreviewacross 84+ POSTs. The condensed feed is the suspected loss point. The №20 gap item (check node-side raw logs) remains open and unexecuted.
⟳ MSIE-forgery .env census (single-node passes, three UAs) — hostile, recurring shape, unnamed
- Actors: Unattributed, empty
clientIp. Three passes on canary-farm-1 and control-1: farm MSIE 7.0 10:30:43 09-14 (170 events, 169 paths, 1 mint at/.env), farm Safari/125 PPC 19:02 09-14 (113 events, 112 paths), farm MSIE 8.0 07:35:55 09-15 (114 events, 112 paths, 1 mint at/.env), control MSIE 7.0 04:15–04:16 09-15 (114 events, 112 paths). - TTPs:
.env-variant and.env.<ext>census wordlists. Only 41 of 169 farm MSIE-7 paths overlap the MSIE-8 list. All four passes mint exactly once at/.envor fail once. - Assessment: The same wordlist family runs under rotating antique-browser forgeries one pass per node. This matches the CREDSWEEP-lineage one-pass-per-UA shape from №13–№14. Promotion trigger: a third pass on a new node with a shared wordlist.
Standing actors (persistence check)
- frantech Chrome/114
/c/crawler — 4th consecutive window on frantech-ts: 430 events / 430 unique random-token paths in this window, 1,099 all-time since the node went live 09-12. Fixed shape: ~20 events per hour across 4 vanity Host headers (we-love-the.world,raw.bunnyfeet.baby,tls.bunnyfeet.baby,make-internet-safer-for-the.world). Slow growth, same shape. - 40.87.20.23 (Azure) — broke its on-schedule pattern: zero events this window after two scheduled single-mint appearances (№19, №20). Its 1:1 events-to-mints ratio now rests on two data points.
- 93.152.209.9/.10/.11 (Omniline Investment s.r.o., BG) — three sibling IPs, first-ever appearance, 5 events each,
/-only tarpit handshakes within 3 minutes. Same shape as the benign/-prober pool. Watch only. - Absent: 194.180.49.37 and 91.245.74.31 (second window), 80.94.95.211 (third), 176.65.148.71 (second), 45.148.10.238 (fourth), 94.154.46.x block (second), 136.117.52.210 (the №20 named runner — its TTL expired unused), 35.245.185.138 and 45.67.211.147 (the use IPs), 204.76.203.x, NIGHTAGENT (fourth idle window), XMLRPC-BRUTE (fourth near-silent window: 4 stray GETs, 2 POSTs, no bodies).
- frantech Chrome/114 census carries the
/c/random-token enumeration only — its 09-12 non-/c/rows (/@fs/proc/self/environ,/.cursor/mcp.json,Jenkinsfile) did not return in this window.
Canary credentials
Summary
No canary credentials were used in AWS during the window. Fleet sensors minted 5 credentials to 0 collector IPs. None reached AWS.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 5 |
| Distinct collector IPs | 0 |
| Credentials used in AWS (alerts) | 0 |
| Credentials stolen, no observed AWS use in window | 5 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
None: 37 mints, 2026-09-12 08:14 → 2026-09-15 07:29136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:41136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:5534.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:4434.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0935.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52167.99.79.44: 12 mints, 2026-09-08 19:11 → 2026-09-11 18:1994.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:4894.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:1394.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:5180.94.95.211: 5 mints, 2026-09-08 18:11 → 2026-09-12 02:32136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:56142.93.129.190: 3 mints, 2026-09-09 06:26 → 2026-09-10 20:2341.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:45
Canary-use attribution (briefing prose)
All 5 window mints trace to the census campaigns: the 511-path ENV-CENSUS-3 run (aidev 10:20:26), the 59-path ENV-CENSUS-4 stagger (aidev 12:31:16, farm 13:23:35), the MSIE-7 farm pass (10:30:43), the MSIE-8 farm pass (07:35:55 09-15), the ru-edge Firefox/3.0b5 census (18:11:14), and the control Firefox/116 probe (11:29:09 09-15). The flux feed logged 7 issued rows. Tracebit's 5-credential count differs because mint rows can carry 200-family result labels (the №20 mint-label quirk).
The 136.117.52.210 TTL question closed this cycle: its 26 credentials expired by 12:41 UTC 09-14 with zero AWS callbacks. The named METADATA-HUNT runner is a hoarder, not a consumer — its mint pattern now matches the 34.x GCP runners (25-mint batches, no use). The standing hoard across all named collectors is 190+ credentials with 2 use events ever. The fleet's deny-first IAM posture remains the load-bearing control.
The /46 block's only window activity was 2 upstream-rejected mint attempts (94.154.43.164 aidev, 94.154.43.146 farm, both /.env at 09:41–09:42 09-15 under forged Chrome/147) — the pool probes from №16 returned without a mint.
Fleet Observations
- Canary economics: 7
issuedrows / 5 distinct credentials (Tracebit) and 81 upstream rejections (aidev 32, ru-edge 22, control 18, farm 9). Failure ratio 11.6:1, the highest on record. The two METADATA-HUNT bursts drove 13 rejections each, and the 09-15 06:00 ru-edge burst added 13 more. All mints and rejections areaws-type at/.env-family paths. The concentration follows burst speed, not capability — every rejection clusters inside a fast burst minute. - Attribution gap held at 91%: 15,199 of 19,639 window rows carry an empty
clientIp(100% on control/frantech/netcup/ru-edge/sponge, 91.4% on aidev, 91.9% on farm). Only 21 unique named IPs appeared fleet-wide. 14 of them belong to 5 benign-shape/-handshake groups or the 4 REGISTRY-HUNT runners. The socket-peer fix (carried since №17) remains the highest-value change available. - XFF forgery held: 431 requests carried
X-Forwarded-For, 0 multi-entry chains, 0 loopback rows. Eleventh clean window. - TLS/attribution posture: farm logged 96 https events on
sso.rightabouteverything.show(205 Host-header hits), aidev 323 oninference.fapthropic.com, the five certless nodes 0. Thewe-love-the.world/bunnyfeet.babyHost cluster on frantech (430 events) belongs to the standing Chrome/114/c/crawler, not TLS probing. - Control discovery velocity: day 20: 5,378 events, 0 attributable IPs, +76% over the 7-day baseline — the largest single-day jump since the node went live, and all of it census-driven (22:00 09-14 OMEGA burst 1,058, 03:00 09-15 1,121, 09:00 09-15 625). Ramp series: 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → blind ×3 → 51 → 52 → blind → blind.
- Result-tag spikes: all attributed. frantech
not-handled2,034 (3.1×) = the OMEGA 150-path passes plus the ALIYUN-PROBE 404-path census. ru-edgenot-handled2,769 (4.3×) = the 1,584-path OMEGA burst plus the METADATA-HUNT burst. Theapp-config-*andenv-production-errorspikes on aidev/control/ru-edge split between OMEGA, METADATA-HUNT, ENV-CENSUS-3/4, and the MSIE passes.fake-git-error76 on control (11.4×) sits inside the OMEGA 22:00 burst. - New UA inventory (hostile-shaped):
Mozilla/5.0 (compatible; KGBMasscann/1.0)(netcup, 1 event),distort-scanner/1.0(control, 1 event,/bomba/), andnmap-http-info(netcup, 1). Benign: CensysInspect 60 events fleet-wide, Palo Alto Cortex Xpanse 57, InternetMeasurement 7, zgrab singles. The single-event UAs are inventory, not campaigns — both hit one path each.
SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)
- New commands: the digest reports 0 of 61 distinct as new this window under its day-file window. Two operators outside the commodity loop ran diverse command sets worth naming: 171.220.244.134 (25 distinct commands, 60 events) and 115.243.248.82 (24 commands, 50 events). Both ran the same three-stage pattern: hardware recon (
uname,lscpu | grep Model,df -h | head -n 2 | awk 'FNR == 2 {print $2;}'), then an interactive password reset (echo "P@ssword\nKOmAFWAU9Pq0\nKOmAFWAU9Pq0"|passwdandecho "root:uJIi6LscOIh1"|chpasswd|bash), then the standardrm -rf .ssh+ authorized-keys inject. The password-reset stage is the first post-compromise persistence step the feed has shown beyond the key-plant. - Password-reset loop widening: 8 IPs ran
passwd/chpasswdvariants this window (171.220.244.134 ×8, 115.243.248.82 ×7, 115.191.32.68 ×5, 115.190.151.242 ×4). Each IP tries several fresh passwords per session — persistence automation, not one-shot defacement. - Funnel: 335 sources sent credentials → 245 got a shell (73%) → 118 ran a command (48% of shell-getters, 35% of sources). Event level: 22,210 attempts → 14,604 accepted logins → 8,299 commands (57% of accepted logins run something). Per-login conversion held from №20.
- Credentials: 7,737 distinct pairs, 0 new. Concentration unchanged: the
345gs5662d34/3245gs5662d34family owns the top rows (1,066 + 776 + 67 + 60 attempts across 4 usernames) — commodity noise.
Gaps / Next Collection
- ALIYUN-PROBE recurrence. The 404-path rotating-UA census ran on 3 nodes at 03:30, 08:47, and 09:28 UTC 09-15. If a fourth node appears (sponge, netcup, farm), the campaign is fleet-wide automation. Check its 21-path
/.aliyun/*sub-list against the OMEGA frantech expansion — both introduced Aliyun/Qcloud paths this window. - ENV-CENSUS-4 wordlist linkage. The 59-path Chrome/126 list shares only 13 paths with the 511-path ENV-CENSUS-3 list but ran the same morning with the same UA. Pull both lists side by side next cycle and check the 46 non-shared paths against №20's 511-path list. A match would merge the campaigns.
- LIBREDTAIL dropper capture, second pass (carried from №20). Three windows with zero POST bodies. Next cycle, read the node-side raw flux logs on one run directly, before the condensed feed, to find where
bodyPreviewdies. - frantech Chrome/114
/c/crawler identity. Four consecutive windows of ~20 hourly random-token fetches under 4 vanity Host headers. Check whether the tokens resolve anywhere (DNS logs, pcap sensor) or whether the pattern precedes the flux sensor on another host — the condensed hp feed starts 09-12, same day as the node. - Socket-peer logging for headerless requests (carried from №17–№20). 91.9% of this window's rows are unattributed. OMEGA-SWEEP, METADATA-HUNT, ENV-CENSUS-3/4, ALIYUN-PROBE, and the MSIE passes all attribute at once if it ships. No fleet-side action from this workflow.
- CURL-SWEEP retirement. Fourth consecutive miss. Registry entry moves to standing-paused this cycle.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-15.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (154.12.227.198, 136.117.52.210), plus 30 ad-hoc v_full queries (burst attribution per node-hour, OMEGA-SWEEP wordlist identity and subset tests, METADATA-HUNT burst pairing, ENV-CENSUS-4 stagger timing and wordlist overlap, ALIYUN-PROBE pass linkage, MSIE census linkage, Firefox/3.0.9 + 3.0b5 census family, MALWARE-DICT-2 family growth, XFF multi-entry check, /46-block check, 40.87.20.23 absence, hp operator diversity and password-reset loop).