FLUX FLEET — INTEL BRIEFING №5
Period: 1–2 Sep 2026 (24h, day 5 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 5-day baselines populated)
Related: Briefing №4 (docs/intel/flux-fleet-intel-briefing-2026-09-01.md); digest medina:/data/flux-logs/reports/flux-digest-2026-09-01.md
BLUF
The quietest day since day 2 (13.3K events, −53% fleet-wide) delivered the campaign forecast's first miss and two new industrial campaigns: neither the XMLRPC-BRUTE nor the MALWARE-DICT replay returned on schedule, superseding the daily-cadence judgement — their automation runs intermittently, not daily. In their place, an Omegatech /24 pair ran the largest trap-family sweeps in fleet history (117 and 107 families) across farm and control, and a 1337 Services pair executed 1,000 POSTs each against 5 paths on both EU nodes — identical volume per node, another replayed tooling signature. METADATA-HUNT returned after a 3-day gap with the exact 130-family/533-path/12-POST shape of its day-1 debut, and the Azure GIT-VAULT family rotated IPs and collected another /.env mint. 88 canaries minted (fleet ~273) but mint failures returned: 22× HTTP 400 (16 on aidev) — first tracebit errors in 48h, requiring investigation.
Key Judgements
- Replay automation is intermittent, not daily. The XMLRPC-BRUTE (8,146 POSTs) and MALWARE-DICT (12,707 paths) — predicted to return on schedule after two consecutive identical-volume days — were absent entirely on day 5. Their cadence is better modeled as burst windows (multi-day runs, then gaps) than cron-daily. Briefing №4's "expect both again tomorrow" is superseded; treat identical-volume recurrence as confirmation of tooling, not schedule. (High confidence — direct absence)
- Family-count records are being set and broken daily by the same /24. Omegatech 94.154.46.243 (farm, 3,538 events, 117 families, 1,674 paths) and 94.154.46.250 (control, 1,050 events, 107 families, 1,042 paths) exceed RMP Protection's day-4 93-family record — the template-sweep ceiling keeps rising, and the two IPs ran within hours of each other from one /24. Industrial sweep tooling is converging on the fleet from multiple providers. (High confidence)
- POST-heavy 5-path floods are a new pattern. The 1337 Services pair (185.19.40.36 aidev / 185.19.40.40 farm, "bulletproof-adjacent" NL GmbH) sent exactly 1,007 events with 1,000 POSTs across 5 paths on each node — volume-identical cross-node, minute-scale execution. Same fingerprint-replay behavior as MALWARE-DICT/XMLRPC but new tooling; 1,000 POSTs to 5 paths is credential-stuffing or form-spam cadence, not recon. (High confidence — volume math)
- Canary mint failures are back and clustered. 22 tracebit HTTP-400 mint failures (aidev 16, control 3, farm 3) after two clean days — including visible
/.env [tracebit-http-error]failures in the kill-chain journeys of the GCP METADATA-HUNT pair and Azure 20.186.237.132. Either a Tracebit API-side change or a key/quota degradation; the day-2 aidev-400 episode (fixed then) looks recurrent. (High confidence — direct observation; cause undetermined)
Active Campaigns (day 5 status)
⚠ NEW: OMEGA-SWEEP (record-scale template sweep) — hostile, industrial
- Actors: 94.154.46.243 (farm: 3,538 events, 117 families, 1,674 paths) + 94.154.46.250 (control: 1,050 events, 107 families, 1,042 paths) — Omegatech LTD, US-registered, same /24
- TTPs: full-stack dev-ops census — git internals,
docker-compose.yml(+override),wp-config.{bak,old,php.bak,php.save},composer.{json,lock},settings.py,/.ssh/authorized_keys,/.circleci/config.yml,/.dockerenv, plus the fleet's first/.config.env,/.env.k8s,/.shopify/credentials,/contentful/.env,/dynatrace/.env(SaaS-credential expansion),/accounts.txt - Assessment: new record-holder for family breadth; the SaaS-credential path expansion (Shopify, Contentful, Dynatrace, k8s secrets) shows wordlist tracking of cloud-native secret locations. Watch for a third /24 node tomorrow
⚠ NEW: POST-STORM (identical-volume POST flood, 1337 Services) — hostile, industrial
- Actors: 185.19.40.36 (aidev) + 185.19.40.40 (farm) — 1337 Services GmbH (NL), 1,007 events each, 5 paths, 1,000 POSTs each (aidev 14:55–15:00 UTC, farm 05:16–05:17 UTC)
- Assessment: volume-identical cross-node POST flood — feed-replayed brute/stuffing tooling against a fixed 5-path set. The "1337 Services" ASN joins Feo Prest/SS-Net in the bulletproof-adjacent tier. POST body hashes from the digest will identify the target set
⟳ METADATA-HUNT — day 5 return, 3-day gap, shape-identical to day 1
- 34.74.98.8 (control) + 34.86.163.64 (aidev) — Google Cloud, US — 130/131 families, 533 paths, 12 POSTs, single-minute bursts. Journeys carry the day-1 fingerprints:
__aws_leak_probe_*, Vite@fs/proc/self/environ,/etc/passwd,/.aws/credentials,/.azure/credentials,@fs/*/…/.aws/credentials,/.mcp.json. The GCP scan platform identified in Briefing №2 is back on-cadence
⟳ GIT-VAULT (Azure secret harvester) — day 5, IP rotation + another mint
- New IPs, same 26–30-family git-internals +
.env+.git-credentials+database.yml/secrets.ymlchain: 20.168.100.246 (aidev — collected a/.env [issued]canary mint) and 20.186.237.132 (control; its/.envmint attempt hit tracebit 400). Second consecutive day the Microsoft-hosted family harvests mints
⟳ SS-NET TOOLING — day 5, now signature-tracked fleet-wide
- New signature
6a6fdaca6a1f(first seen 09-02, 3 IPs, 486 events, ⚠FLEET-WIDE): the.env-variant walk (/.env [issued]→/api/.env→/backend/.env→/phpinfo.php→/admin/.env…) now has its own cross-node signature. SS-Net proper (80.94.95.211) hit aidev (149 events); TechTies (91.92.47.201) returned to farm and collected a third/.env [issued]mint — the most consistent mint-collector in the fleet
⟳ PHPSWEEP kit — day 5, third provider
- SoloRDP 103.215.74.26 (aidev, 92 events/78 POSTs) continues; DIGI VPS 103.168.67.253 (farm, 118 events/78 POSTs, identical 12 paths) joins — the RCE-verify-then-exploit chain now observed from three providers (Techoff, SoloRDP, DIGI VPS). Commoditization judgement from №4 strengthened
⟳ REGISTRY-HUNT — day 5, fifth IP set
- 9+ fresh DigitalOcean IPs across both EU nodes (164.90.228.79, 167.99.182.39, 167.71.175.236, 64.227.32.66, 157.245.36.108, 146.190.242.161, 139.59.132.8, 165.227.173.41), byte-identical 12-step journey, 25–27 families each. Five days, five IP sets. Still control-averse
⟳ WP-BATCH / NIGHTAGENT — day 5, component persists, trio rests
- The wp-batch SQLi component ran independently again (signature
1de56f9af5ba⟳, 210 events, 2 IPs, both EU nodes) — but none of the three residential NightAgent IPs appear in today's top talkers or watchlist. First day the full chain's trio was absent; the detached wp-batch component carried on. Watch for roster return
⟳ RCE-SWARM — day 5, thinning
- 2 IPs across aidev+control (98 events, signature
7e61a9500d8b⟳, day 5 of 5). The phpunit/CGI chain's volume is fading but the signature persists
Standing actors (persistence check)
- Pfcloud UG (204.76.203.18, ipsum:2) — day 5 of unbroken control recon (2,327 more events, 578 paths). Five days unbroken
- Feo Prest (213.209.159.154, DE) — new IP from the day-1 org, hit control AND farm (169+168 events) — cross-node rotation continues
- UCLOUD (152.32.235.160, ipsum:3) — repeat aidev visitor (133 events, 2 paths, zero POSTs) — narrow-focus probe pattern persists
l9explore/1.2.2+python-httpx/0.26.0— new exploitation-tooling UAs on aidev;l9exploreis a known credential-exploitation framework. Watch its source IP
Fleet Observations
- Canary economics day 5: 88 mints (farm 48 — aws/ssh/http mix, control 20 aws, aidev 20 aws), fleet total ~273 tripwires — but 22 mint failures (HTTP 400): aidev 16, control 3, farm 3. First failures since the day-2 episode; visible as
tracebit-http-errorin live journeys (GCP pair, Azure 20.186.237.132). This is a fleet-health regression, not attacker behavior — investigate the Tracebit key/quota path first - Mints into hostile hands: ≥3 more
/.env [issued]collections this window (TechTies, Azure 20.168.100.246, plus the fleet-wide SS-Net-signature journey). Cumulative hand-to-hostile count now ~6+; the callback surface keeps growing - Volume collapse with IP continuity: 13.3K events fleet-wide (−53%) yet unique-IP counts held (139/91/114) — the bursts (xmlrpc, malware-dict, Techoff) were the volume, and their absence returned the fleet to broad low-intensity scanning. Fleet totals: ~93K log lines / 5 days
- Control ramp: unique IPs 39 → 70 → 88 → 107 → 114 — five consecutive daily increases even as events fell 68%; breadth still growing while burst volume pauses
- XFF forgery quiet, third day: 345 single-entry XFF, zero forged chains, zero empty-clientIp
- TLS: farm 106 https (CT-cert draw falling with volume), aidev 107 (~4%,
inference.fapthropic.com1,234 events — up), control certless. First appearance ofvmi3243483.contaboserver.netas Host on farm (7 events) — an rDNS-resolved hostname probe of the farm IP, minor recon signal
Gaps / Next Collection
- Tracebit 400 investigation is now priority one — 22 failures on day 5 after two clean days. Check the Tracebit key validity (JWT claims intact), quota consumption, and API-side errors; the day-2 fix pattern (mangled key) may have recurred. Digest improvement candidate: alert on any nonzero mint-failure count in the fleet overview
- POST-STORM's 5-path POST target set — pull the digest's body-hash data for 185.19.40.36/.40 to identify what 1,000 POSTs were aimed at (candidate: login/otp/xmlrpc surfaces)
- Cross-node IP-reuse flagging (carried №3/№4) — OMEGA-SWEEP's /24, Feo Prest's cross-node rotation, and the fleet-wide signatures still aren't auto-surfaced
- Per-IP spike normalization (carried) — today's −56% control delta shows raw-count baselines swing wildly with burst absence; normalization would have predicted a quieter day
l9explore/1.2.2UA provenance — identify the aidev source IP and journey; known tooling on the AI surface deserves a dedicated watch row