FLUX FLEET — INTEL BRIEFING №5
Period: 1–2 Sep 2026 (24h digest window ending 19:10 UTC 2026-09-02; day 6 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 7-day baseline, every burst ≥50 events attributed by spot query)
Same-day rerun №3: this digest window overlaps №7's by ~23.6 h. The only new data is the 18:45–19:10 UTC slice: 12 events, all shallow. Every number below was re-verified against the full window; claims that only the added minutes could change are marked as new-slice findings. All times are UTC.
BLUF
No named campaign moved after №7's 18:45 UTC horizon. The new slice holds 12 events: a zgrab Tomcat-manager probe from the Microsoft range (48.217.235.189, control, 19:06), a single ivre-masscan/1.3 probe (187.108.1.142, Brazil, 19:07), and a 10-event browser-pattern visit on aidev (104.248.127.55, DigitalOcean, 18:47, two /favicon.ico fetches). The fleet is quiet: no mint since 16:31 UTC, no hostile POST in the new slice, zero XFF forgery for the fifth consecutive day. The window's one addition to the actor registry is 192.253.248.173 (Limited Network LTD, NL, ipsum:3): a 138-event, 32-family credential census on control-1 at 11:37 UTC that took one /.env mint. Canary economics stay healthy: 60 mints in the window, 8 upstream 400s all on 09-01, zero 401s.
Key Judgements
- The XMLRPC-BRUTE scheduler prediction is now testable: the next 1,000-POST burst is due near 07:25 UTC on 09-03. 185.19.40.40 ran two bursts on the farm (05:16:40–05:17:35 and 18:25:22–18:26:07), ~13 hours apart. The all-time
/xmlrpc.phpPOST census is 19,292 from 4 IPs: 34.63.40.186 (8,146, aidev, day 2), 136.119.157.160 (8,146, farm, day 3), 185.19.40.36 (1,000, aidev), 185.19.40.40 (2,000, farm). (High confidence — burst timestamps from raw logs; POST census by direct query) - The Omegatech /24 rotation pool shows no fifth IP; the operator's second range is active. The last 94.154.46.x sweep was .249 at 13:08 UTC. 130.12.180.77 (Omegatech LTD by ASN, separate range) ran a 61-event credential sweep on aidev at 00:04–00:07 UTC and took 3 mints. №7's "possibly the same operator's second pool" is now the better read. (Moderate confidence — one ASN match plus one sweep; no whois research yet)
- Control-1's discovery velocity has flattened at 106–107 unique IPs per day. The ramp reads 39 → 70 → 88 → 107 → 106 over five days. Volume fell to 4,084 events because the day-3/4 burst baseline is aging out, not because discovery slowed. The fresh-IP differential is saturating; the node now measures steady-state internet background. (Moderate confidence — two-day plateau is short; the long-term dataset continues)
- 192.253.248.173 is a new kill-chain-grade actor in the small-rotator class. Limited Network LTD (AS213790, NL),
ipsum:3, control-1 only, 138 events in 63 seconds (11:37:27–11:38:30), 32 result families, 8-UA browser rotation, one/.envmint. The template matches 107.173.160.158 (ColoCrossing): single-minute census, rotating UAs, one mint. (High confidence — journey, UA set, and mint verified by direct query)
Active Campaigns (day 6 status)
⟳ XMLRPC-BRUTE / 1337 Services — hostile, scheduled
- Actors: 185.19.40.40 (farm, 2,000 POSTs in two bursts this window) and 185.19.40.36 (aidev, 1,000, 09-01 14:55) — 1337 Services GmbH (NL). Historical runners: 34.63.40.186, 136.119.157.160.
- TTPs: 4-path WP recon, then 1,000 POSTs to
/xmlrpc.phpin ~45 seconds, each body a distinctwp.getUsersBlogscredential pair, forged Chrome/78 UA. No new burst in the new slice. - Assessment: The farm is the standing target. The cadence forecast from №7 (next burst ~13 h after 18:26) is the top watch item for the next cycle.
⟳ OMEGA-SWEEP (Omegatech /24 + second range) — hostile, paused at four /24 IPs
- Actors: This window: .248 (aidev, 1,390 events, 10 mints), .249 (farm, 2,100, 12), .250 (control, 1,050, 4) — all forged Googlebot UAs — plus 130.12.180.77 (aidev, 61 events, 3 mints, honest Chrome/131 UA).
- TTPs: 93–107-family credential census in a single minute; SaaS, AI-stack, and cloud-credential paths;
/.ssh/id_rsa(50 aidev events from .248). - Assessment: 26 of the window's mints came from the /24 trio, unchanged from №7. No fifth /24 IP appeared; the pool may hold exactly four. 130.12.180.77's honest UA and slower pace (3.2 minutes) mark it as a different runner in the same ASN.
⟳ RCE-SWARM / libredtail kit — hostile, commoditized
- Actors: 27 IPs, 1,127 events, all 6 days, all 3 nodes. This window: 103.118.29.32 (control, 49), 217.160.171.212 and 103.205.107.170 (aidev, 49 each), 38.64.56.25 (control, 6). No new source IP in the new slice.
- TTPs: PHP-CGI
/bin/shchain, phpunit CVE-2017-9841, docker/containers/json, dropper fetch tohttps://217.60.195.113/sh. The three 49-event runs confirm a fixed kit script. - Assessment: The payload host enters day 7 as the fleet's most stable hostile indicator, with zero observed callbacks.
⟳ SS-NET TOOLING — hostile, standing
- Actors: 80.94.95.211 (SS-Net, RO): aidev 149 events (09-01 23:37, 2 mints) and farm 171 (09-02 06:18, 1 mint). Signature
6a6fdaca6a1fnow reads 3 IPs / 488 events / both EU nodes — the fingerprinter merged this actor with Feo Prest 213.209.159.154 (168 events, 1 mint, 02:53). Two operators, one.env-variant wordlist; the merge is a digest artifact, not a campaign merge. - TTPs:
.env-variant walk, per-request rotating stale-browser UAs. - Assessment: Three mints across both EU nodes this window; day 7 of standing presence. The 91.92.47.201 sibling did not appear.
⟳ GIT-VAULT (Azure range) — hostile, declining
- Actors: 20.102.46.145 (control, 5 events, 01:22) and single-event touches from 20.163.170.178 and 20.163.34.21. Down from 30–73-event bursts on 09-01.
- TTPs: Git-internals and credential-file paths, rotating UA set.
- Assessment: The Azure pool is still present but its volume collapsed. No mints.
⚠ NEW (minor): WP-ENUM (45.156.129.136) — hostile, one burst
- Actors: 45.156.129.136 (Sistemas Informaticos, AS211680; 45.156.129.57 from the same /24 appears in the single-probe noise floor). Control-1, 40 events, 02:38:58–02:42:38.
- TTPs: WordPress plugin
readme.txtcensus (20+ plugins incl. wpforms-lite, rank-math, wps-hide-login),/wp-json,/license.txt, then/owncloud/status.php,/console,/WebInterface/,/index.jsp. UAMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/12…— a bare Chrome string with no platform, a forged or stripped UA. No POSTs, no mints. - Assessment: Version-fingerprint recon for a WordPress target that does not exist. Human-pace gaps (10–30 s) suggest a scripted walk with delays, not a browser. Watch for the /24 rotating like CREDSWEEP's ranges.
Standing actors (persistence check)
- Pfcloud UG (204.76.203.18,
ipsum:2, NL) — day 6 of continuous control recon. Daily events: 1,871 → 1,759 → 1,829 → 2,008 → 1,590 (09-02 partial at digest time). Empty UA, zero POSTs, ~576 distinct paths/day. Volume is flat: this is a fixed-path-census service, not an escalating actor. - LeakIX (
l9scan, DigitalOcean rotation) — 9 farm mints in the 15:13–15:20 wave plus 164.90.228.79 on both EU nodes; 12 window mints total, the most consistent collector. Borderline-benign;l9explore/1.2.2(193.32.204.199) touched all 3 nodes 09-01 19:56 → 09-02 04:44. - 194.180.49.37 (Go-http-client) — 7 events across aidev and control this window (last 09-02 01:51); 16 mints over 4 days all-time. Still the most persistent single-IP mint collector.
- 2.58.14.186 — 2 aidev mints (15:28, 16:31), stale Chrome/81. Second consecutive day; promote to standing if it returns tomorrow.
- 91.92.41.55 — 2 aidev mints window (09:53, 14:41), stale Chrome/81. Third day of low-volume minting.
- 107.173.160.158 (ColoCrossing) — control, 27 events, 1 mint, 13:38. Second day, same 28-path template. 192.253.248.173 now matches this class.
- 130.12.180.77 — see OMEGA-SWEEP; 3 mints mark it as a real collector, not just sweep noise.
New-slice actors (18:45–19:10 UTC)
- 48.217.235.189 (Microsoft, AS8075) — single
zgrab/0.xGET/manager/htmlon control, 19:06, 404. Second Tomcat-manager probe of the day (40.124.179.169 hit aidev at 18:43, №7's horizon). Research-scanner tooling from a cloud range; watch for a Microsoft-hosted follow-on. - 187.108.1.142 (SIM INTERNET, BR,
ivre-masscan/1.3) — single/tarpit probe, 19:07. Honest research UA; benign list. - 104.248.127.55 (DigitalOcean) — 10 tarpit events on aidev, 18:47:44–18:47:56, Chrome/142 UA, two
/favicon.icofetches. The favicon pattern is browser behavior; this is the new slice's only candidate for a human or headless-browser visit. Shallow, no traps hit.
Benign / research (not hostile)
- 80.82.77.202 (IP Volume inc,
ipsum:4+firehol2) — 3-node fixed-cadence/handshake, 191 events, unchanged. - 93.174.93.12 — same prober family, 85 events on all 3 nodes. TTP change: it now rotates forged browser UAs (FreeBSD Firefox/54, Mac Safari) alongside
Python/3.10 aiohttp/3.8.4. Journeys stay/-only, so it stays on the benign list, but the UA rotation removes the "fixed-cadence uptime prober" simplicity. - ivre-masscan/1.3 — one probe; research scanner, new to the benign list.
- Cloud noise floor — signatures
f08ba4e565d4(67 IPs),975b7f9fdedf(50 IPs),15b31aa4c37c(27 IPs): one-event/tarpit touches from Tencent, GCP, Azure, and bulletproof-hosting ranges. The digest's 48-IP3e1c5eb879e7cluster is this floor plus the two aiohttp probers.
Fleet Observations
- Canary economics: 60 mints in the window (control 8 / aidev 29 / farm 23), all type
["aws"], 12–13 distinct minting IPs per node. All-time/.envissued: 281 (aidev 123 from 74 IPs, farm 108 from 43, control 50 from 12) — unchanged since 16:31 UTC; the last 2.7 h produced no mints. Mint failures: 8 × 400, all on 09-01 between 15:56 and 21:19, none in the ~22 h before the digest ran. Zero 401s (key intact). Actor split: 5 LeakIX, 2 Omegatech .250, 1 Azure 20.57.206.149 — same root cause as №6/№7 (upstream 400 tied to scanner request patterns). - XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows, fifth consecutive clean day post-fix. 461 single-entry XFF requests in the digest window (493 in the wider spot-query window).
- TLS/attribution posture: farm 235 https events with
sso.rightabouteverything.showat 2,460 Host events; aidev 219 https withinference.fapthropic.comat 394. Both TLS identities hold traffic at or above their plain-IP Host shares; the attribution design keeps validating. - Volume: digest window totals 13,251 events (farm 5,344 / aidev 3,823 / control 4,084) vs the spot query's 13,444 (farm 5,380 / aidev 3,911 / control 4,153). The 193-event gap is the known +4 h timestamp-cast quirk at the window's open end. Control's −63% vs the 7-day average is the day-3/4 burst baseline aging out. Every hour ≥50 events is attributed: farm 05:00 and 18:00 = the two 1337 replays, farm 13:00 = Omegatech .249, aidev 12:00 = Omegatech .248, aidev 13:00 = Jio fuzzer, farm/aidev 15:00 = l9scan wave, control 09-01 15:00 = Omegatech .250, control 11:00 = 192.253.248.173 + Pfcloud.
- Spike attribution (all causes found): aidev fake-svn 1,162 + fake-git 144 = Jio fuzzer 49.43.3.194 (
/config/config/...recursion); aidev fake-git remainder = Omegatech .248 (14); phpinfo 25 = 45.153.34.43 (12) + .248 (6) + floor; ssh-private-key-error aidev 50 = .248, control 34 = .250 (27) + 192.253.248.173 (7); webshell-probe 23 = .248 (22); farm backup-archive 22, k8s-secret-manifest 22, config-json 23 = .249 census; control app-config-python 21 = .250 (20). No unexplained spike remains. - Cross-node reuse: 24 IPs on 2+ sensors. Hostile: 80.94.95.211 (320, both EU nodes), LeakIX 164.90.228.79 (82). Benign/shallow: the aiohttp pair,
l9explore, Tencent 43.x range, 144.202.92.17 / 195.182.16.23 / 77.83.39.94 (≤15 events each,/-only). New to the list: 165.232.84.100 (18 events, farm + aidev, DigitalOcean, shallow). - Infrastructure: no fleet-side changes this cycle.
- Digest quirks applied: window overlap with №7 (23.6 h) — only post-18:45 events counted as new, verified against raw log strings. First-seen tables read as inventories: the
opendirme-credhunt/1.0"first-seen" is 45.55.44.248's already-known 11:30:48 burst (12 paths in 55 ms, 1 mint, AI-CREDHUNT's only window appearance)./manager/htmland/administratorfirst-seens are single shallow probes (zgrab, 5.59.248.185). The new-UA list resolves entirely to known actors: 93.174.93.12, 107.173.160.158, 192.253.248.173, 154.83.197.57. The+4 htimestamp cast and single-writer DuckDB lock (parallel spot queries fail; rerun sequentially) both re-confirmed.
Gaps / Next Collection
- 1337 burst scheduler — the next farm burst is due near 07:25 UTC on 09-03 (~13 h after 18:26). A confirmed third interval fixes the cadence and lets tarpit budget be pre-allocated. Highest-value watch item.
- 217.60.195.113 payload host — day 7, 27 source IPs, zero callbacks. Passive DNS / threat-intel lookup still open (carried №6–№7).
- 192.253.248.173 recurrence — first appearance of a
ipsum:3Limited Network LTD rotator with a mint. If it returns on a new IP with the same 32-family template, promote it to a named campaign alongside 107.173.160.158's class. - Omegatech provenance — whois on 94.154.46.0/24 still open; the /24 pool may be exhausted at four IPs, which makes 130.12.180.77's range the next rotation to watch.
- 104.248.127.55 — the new slice's only browser-pattern visitor (favicon fetches). One visit is not a pattern; a recurrence with deeper paths would mark operator interest in the aidev surface.
- Cross-node auto-flagging — still absent from the digest; reuse tables remain a spot-query artifact (carried №3–№7).
Generated on medina (local run, systemd headless). Digest: /data/flux-logs/reports/flux-digest-2026-09-02.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, plus 14 ad-hoc v_full queries (spike attribution, journey fingerprints, all-time actor censuses) and raw-log verification.