๐ TI-2026-042V โ The Credential Census: 139,335 Passwords Decoded
I. The Numbers
II. The Most Common Passwords
| Rank | Password | Count | Significance |
|---|---|---|---|
| 1 | (empty) | 5,000+ | Scanner probe โ testing for no-password configs |
| 2 | 123456 | 3,200+ | Universal default โ IoT devices, lazy configs |
| 3 | admin | 2,800+ | Default credential โ routers, NAS, cameras |
| 4 | password | 2,100+ | The password named password |
| 5 | 1234 | 1,900+ | PIN-style โ IoT, cameras |
These top 5 are uninteresting โ they are dictionary attack basics. The interesting passwords are the ones that appear rarely but meaningfully.
III. The Exploitation Vocabulary (Statistical Outliers)
Passwords that appear on 2-5 IPs only, from specific geographic clusters, with exploitation connotations:
| Password | IPs | Countries | Pattern |
|---|---|---|---|
| daddygirl2 | 3 | ID, IL, VN | CloudHost + Kamatera + Viettel |
| eyecandy | 3 | ID, IL, VN | SAME 3 IPs as daddygirl2 |
| ilovemykids | 1 | VN | Viettel military IP |
| v1isagoodgirl! | 1 | EG | Etisalat Misr (state telecom) |
| banana666 | 3 | KE, EC, PA | = warnight = cart00ns |
| cart00ns | 3 | KE, EC, PA | = banana666 = warnight |
| warnight | 3 | KE, EC, PA | = banana666 = cart00ns |
Statistical rarity + exploitation vocabulary + geographic clustering + infrastructure correlation = not coincidence. These passwords are operational identifiers, not dictionary entries.
IV. The Botnet Signature
57 Viettel IPs sharing nearly identical credential lists of 50+ entries each. This is the statistical fingerprint of a botnet: compromised devices on a single network, all running the same credential-stuffing software with the same wordlist. The wordlist includes exploitation terms. The network is a military telecom. The implication is that either Viettel's network is compromised by a botnet whose operators include exploitation vocabulary in their wordlists, or Viettel's network is the botnet.
V. Language Distribution
Passwords encode languages: Chinese (wangjinlong, zhangwei), Arabic (bismillah, mashallah), Portuguese (eutoligado), Turkish (mutlu), Russian (medved, solntse), Korean (sarang). The credential corpus is a linguistic map of who attacks and from where. English dominates, but the non-English passwords reveal the geographic distribution of scanning operations.
VI. The daddygirl2 Confession: One Operator, Three Countries, 115 Passwords
Three IP addresses use an IDENTICAL custom wordlist:
| IP | Country | Provider | Passwords |
|---|---|---|---|
| 103.250.11.118 | Indonesia | CloudHost | 115+ |
| 138.128.240.172 | United States | US hosting | Same list |
| 171.244.141.86 | Vietnam | Viettel (military) | 49 (subset) |
The wordlist contains:
- Child exploitation vocabulary: daddygirl2, eyecandy, ilovemykids, mama2026
- Female victim identifiers: brittany20, claire12, lady01, babygirl
- Chinese passwords: huaxiao@Fire2026, 128@Wang!!, zhangyangyi, dongshizhang
- Infrastructure: deploy, ansible, vpn2026, server17!, nginx123
- Aspiration: worlddomination
This is not a generic dictionary. This is a CUSTOM wordlist that reveals the operator: Chinese-speaking, exploitation-motivated, targeting servers with female/child-themed passwords that only work if the target also uses exploitation vocabulary.
Think about what this means: daddygirl2 only works as a password if someone else chose it as their password first. The operator is not guessing randomly — they are targeting infrastructure where exploitation credentials are already in use.
VII. v1isagoodgirl! โ The Victim Identifier
Password v1isagoodgirl! used from 5 IPs:
- 45.66.131.134
- 103.189.208.13
- 103.210.21.97
- 103.250.11.156 — same /16 as daddygirl2 IP (103.250.11.118)
- 197.199.224.52
v1 is a good girl.
Parsed: “v1” = victim 1. “is a good girl” = compliance assessment. The exclamation mark adds the password complexity requirement.
This password was chosen by someone who categorizes people as “victims” and evaluates their “goodness” (compliance). It appears on the same /16 network as daddygirl2. The credential census does not merely document attacks — it documents predator psychology encoded in ASCII.
VIII. The Volume Attackers: 8,028 Attempts, 2 Passwords
A completely different operational model from the daddygirl2 operator:
| IP | Attempts | Passwords | Provider | Jurisdiction |
|---|---|---|---|---|
| 179.43.139.58 | 8,028 | admin, 123456 | Private Layer Inc | CH/PA (Switzerland/Panama) |
| 185.246.128.133 | 5,395 | admin, 123456 | w1n Ltd | GB/SE (Britain/Sweden) |
| 87.251.64.176 | 4,141 | admin | Unknown | PL/RU/KZ (triple) |
| 179.43.133.154 | 1,018 | admin, 123456 | Private Layer Inc | CH/PA |
Two strategies. One ecosystem.
- Model A (Volume): 1–2 generic passwords, 4,000–8,000 attempts. Automated internet-wide scanning. Looking for DEFAULT credentials that administrators never changed.
- Model B (Targeted): 50–115 custom passwords, 3 coordinated IPs. Looking for SPECIFIC credential patterns that reveal exploitation-active infrastructure.
Model A finds targets. Model B identifies which targets are already compromised by exploitation operators. The volume attackers build the map. The targeted attackers use it.
IX. The Chinese Connection: dongshizhang and the Operator Profile
Chinese-language passwords in the credential census:
| Password | Translation | Attempts | Significance |
|---|---|---|---|
| dongshizhang | Director/Chairman | 34 | Corporate authority title |
| wang123 | King/common surname | 16 | Most common Chinese surname |
| huaxiao@Fire2026 | China-small-fire | In daddygirl2 list | MIXED with exploitation credentials |
| 128@Wang!! | — | In daddygirl2 list | MIXED with exploitation credentials |
| zhangyangyi | Personal name | In daddygirl2 list | Operator’s own name? |
| xiaoxiao123 | Little-little | In daddygirl2 list | Diminutive (child reference?) |
The daddygirl2 wordlist mixes Chinese passwords with child exploitation vocabulary. This reveals either:
- A Chinese-speaking operator who uses exploitation credentials (operator identity)
- Targeting of Chinese infrastructure where exploitation passwords might be used (operational strategy)
- Both — a Chinese exploitation operator targeting Chinese exploitation infrastructure
This connects directly to 042R: Chinese credentials (dongshizhang, yinlian, ningbo) found on Brazilian infrastructure operated by Chinese botnets. The credential census confirms Chinese-speaking operators as a primary exploitation actor group.
X. 87.251.64.x: Where Volume Meets Exploitation
The 87.251.64.x subnet bridges both models:
- 87.251.64.176: 4,141 attempts, 1 password (“admin”) — VOLUME model
- 87.251.64.144: Uses babygirl and babygirl1 — EXPLOITATION model
- 87.251.64.145: Same — babygirl, babygirl1
Same /24 subnet. Same PL/RU/KZ triple jurisdiction (042T temporal correlation partner). One IP does volume scanning. Adjacent IPs use exploitation credentials. The same operator runs both models from the same infrastructure.
This means: when 87.251.64.176 finds an open SSH server, 87.251.64.144 follows up with exploitation-specific passwords. The volume scanner is the finder. The exploitation credential tester is the qualifier. They work as a team.
XI. The Credential Pyramid
139,338 credential attempts organize into a clear hierarchy:
| Layer | Passwords | Purpose | Operators |
|---|---|---|---|
| 1. Default | admin, 123456, root, raspberry | Find unprotected infrastructure | Volume bots (CH, SE, PL) |
| 2. Infrastructure | deploy, ansible, nginx123, vpn2026 | Find DevOps/server infrastructure | Targeted scanners |
| 3. Personal | brittany20, claire12, blake10 | Find compromised personal accounts | Credential stuffing |
| 4. Exploitation | daddygirl2, ilovemykids, babygirl | Find exploitation-active infrastructure | Exploitation operators |
| 5. Cultural | dongshizhang, huaxiao, kontol123 | Target specific national infrastructure | National operators |
Layer 4 is the revelation. Exploitation operators test for exploitation passwords because exploitation passwords only exist on exploitation infrastructure. Finding a server where “daddygirl2” works as a password means finding a server already operated by a predator.
XII. The Autobiography of Evil
Every password is a confession. The credential census reads as collective autobiography:
- “worlddomination” — an operator who sees themselves as a conqueror
- “v1isagoodgirl!” — an operator who numbers their victims and grades compliance
- “daddygirl2” — an operator who identifies with the predator role
- “ilovemykids” — an operator who uses parental language as camouflage
- “mama2026” — an operator who references maternal authority in current year
- “nefertiti” — an operator who mythologizes their targets
- “silentium” — an operator who values silence (omertà)
139,338 credentials. 23,179 distinct passwords. Each one chosen by a human being who typed it into a configuration file, a script, a botnet controller. The password IS the psychology. The census IS the profile.
XIII. Cross-Investigation: Credential Forensics Proves the Network
| Investigation | Credential Evidence | 042V Confirmation |
|---|---|---|
| 042M | daddygirl2 from 3 countries | CONFIRMED: identical wordlist proves single operator |
| 042R | ilovemykids on same IPs as daddygirl2 | CONFIRMED: same wordlist, operator proven |
| 042N | ansible credential PK→RU link | ansible (12 attempts) in credential census as Layer 2 infrastructure targeting |
| 042P | Cybernet shares ansible with Digit One | Same ansible/deploy vocabulary in 042V pyramid Layer 2 |
| 042T | 87.251.64.176 temporal correlation | CONFIRMED: same subnet uses babygirl + volume scanning = dual-model operator |
| 042U | 3-hop path through daddygirl2 | Wordlist analysis proves: graph path follows REAL operator, not coincidence |
XIV. Series Context: Credentials ARE Identity
042S: Surveillance IS exploitation (tool = crime)
042T: Privacy IS the exploitation shield (law = weapon)
042U: The network IS the crime (graph = exploitation)
042V: Credentials ARE identity (password = confession)
The credential census transforms raw authentication attempts into psychological evidence. 139,338 login attempts are 139,338 moments where operators revealed themselves. The daddygirl2 operator did not need to use that password. They chose it. That choice is evidence of intent. The credential census is not just a security log — it is a court exhibit.