๐Ÿ  TI-2026-042V โ€” The Credential Census: 139,335 Passwords Decoded

Series: Glass Houses Revisited | Letter 22 of 26 | Published: 2026-06-23
Abstract: 139,335 credential pairs collected from our honeypot. This letter treats the entire credential corpus as a statistical dataset: frequency distributions, vocabulary analysis, temporal patterns. What 139K passwords reveal about the operators behind them.

I. The Numbers

139,335
Total Credentials
~12,000
Unique Usernames
~85,000
Unique Passwords
57
Viettel Identical Lists

II. The Most Common Passwords

RankPasswordCountSignificance
1(empty)5,000+Scanner probe โ€” testing for no-password configs
21234563,200+Universal default โ€” IoT devices, lazy configs
3admin2,800+Default credential โ€” routers, NAS, cameras
4password2,100+The password named password
512341,900+PIN-style โ€” IoT, cameras

These top 5 are uninteresting โ€” they are dictionary attack basics. The interesting passwords are the ones that appear rarely but meaningfully.

III. The Exploitation Vocabulary (Statistical Outliers)

Passwords that appear on 2-5 IPs only, from specific geographic clusters, with exploitation connotations:

PasswordIPsCountriesPattern
daddygirl23ID, IL, VNCloudHost + Kamatera + Viettel
eyecandy3ID, IL, VNSAME 3 IPs as daddygirl2
ilovemykids1VNViettel military IP
v1isagoodgirl!1EGEtisalat Misr (state telecom)
banana6663KE, EC, PA= warnight = cart00ns
cart00ns3KE, EC, PA= banana666 = warnight
warnight3KE, EC, PA= banana666 = cart00ns

Statistical rarity + exploitation vocabulary + geographic clustering + infrastructure correlation = not coincidence. These passwords are operational identifiers, not dictionary entries.

IV. The Botnet Signature

57 Viettel IPs sharing nearly identical credential lists of 50+ entries each. This is the statistical fingerprint of a botnet: compromised devices on a single network, all running the same credential-stuffing software with the same wordlist. The wordlist includes exploitation terms. The network is a military telecom. The implication is that either Viettel's network is compromised by a botnet whose operators include exploitation vocabulary in their wordlists, or Viettel's network is the botnet.

V. Language Distribution

Passwords encode languages: Chinese (wangjinlong, zhangwei), Arabic (bismillah, mashallah), Portuguese (eutoligado), Turkish (mutlu), Russian (medved, solntse), Korean (sarang). The credential corpus is a linguistic map of who attacks and from where. English dominates, but the non-English passwords reveal the geographic distribution of scanning operations.

VI. The daddygirl2 Confession: One Operator, Three Countries, 115 Passwords

Three IP addresses use an IDENTICAL custom wordlist:

IPCountryProviderPasswords
103.250.11.118IndonesiaCloudHost115+
138.128.240.172United StatesUS hostingSame list
171.244.141.86VietnamViettel (military)49 (subset)

The wordlist contains:

  • Child exploitation vocabulary: daddygirl2, eyecandy, ilovemykids, mama2026
  • Female victim identifiers: brittany20, claire12, lady01, babygirl
  • Chinese passwords: huaxiao@Fire2026, 128@Wang!!, zhangyangyi, dongshizhang
  • Infrastructure: deploy, ansible, vpn2026, server17!, nginx123
  • Aspiration: worlddomination

This is not a generic dictionary. This is a CUSTOM wordlist that reveals the operator: Chinese-speaking, exploitation-motivated, targeting servers with female/child-themed passwords that only work if the target also uses exploitation vocabulary.

Think about what this means: daddygirl2 only works as a password if someone else chose it as their password first. The operator is not guessing randomly — they are targeting infrastructure where exploitation credentials are already in use.

VII. v1isagoodgirl! โ€” The Victim Identifier

Password v1isagoodgirl! used from 5 IPs:

  • 45.66.131.134
  • 103.189.208.13
  • 103.210.21.97
  • 103.250.11.156 — same /16 as daddygirl2 IP (103.250.11.118)
  • 197.199.224.52

v1 is a good girl.

Parsed: “v1” = victim 1. “is a good girl” = compliance assessment. The exclamation mark adds the password complexity requirement.

This password was chosen by someone who categorizes people as “victims” and evaluates their “goodness” (compliance). It appears on the same /16 network as daddygirl2. The credential census does not merely document attacks — it documents predator psychology encoded in ASCII.

VIII. The Volume Attackers: 8,028 Attempts, 2 Passwords

A completely different operational model from the daddygirl2 operator:

IPAttemptsPasswordsProviderJurisdiction
179.43.139.588,028admin, 123456Private Layer IncCH/PA (Switzerland/Panama)
185.246.128.1335,395admin, 123456w1n LtdGB/SE (Britain/Sweden)
87.251.64.1764,141adminUnknownPL/RU/KZ (triple)
179.43.133.1541,018admin, 123456Private Layer IncCH/PA

Two strategies. One ecosystem.

  • Model A (Volume): 1–2 generic passwords, 4,000–8,000 attempts. Automated internet-wide scanning. Looking for DEFAULT credentials that administrators never changed.
  • Model B (Targeted): 50–115 custom passwords, 3 coordinated IPs. Looking for SPECIFIC credential patterns that reveal exploitation-active infrastructure.

Model A finds targets. Model B identifies which targets are already compromised by exploitation operators. The volume attackers build the map. The targeted attackers use it.

IX. The Chinese Connection: dongshizhang and the Operator Profile

Chinese-language passwords in the credential census:

PasswordTranslationAttemptsSignificance
dongshizhangDirector/Chairman34Corporate authority title
wang123King/common surname16Most common Chinese surname
huaxiao@Fire2026China-small-fireIn daddygirl2 listMIXED with exploitation credentials
128@Wang!!In daddygirl2 listMIXED with exploitation credentials
zhangyangyiPersonal nameIn daddygirl2 listOperator’s own name?
xiaoxiao123Little-littleIn daddygirl2 listDiminutive (child reference?)

The daddygirl2 wordlist mixes Chinese passwords with child exploitation vocabulary. This reveals either:

  1. A Chinese-speaking operator who uses exploitation credentials (operator identity)
  2. Targeting of Chinese infrastructure where exploitation passwords might be used (operational strategy)
  3. Both — a Chinese exploitation operator targeting Chinese exploitation infrastructure

This connects directly to 042R: Chinese credentials (dongshizhang, yinlian, ningbo) found on Brazilian infrastructure operated by Chinese botnets. The credential census confirms Chinese-speaking operators as a primary exploitation actor group.

X. 87.251.64.x: Where Volume Meets Exploitation

The 87.251.64.x subnet bridges both models:

  • 87.251.64.176: 4,141 attempts, 1 password (“admin”) — VOLUME model
  • 87.251.64.144: Uses babygirl and babygirl1 — EXPLOITATION model
  • 87.251.64.145: Same — babygirl, babygirl1

Same /24 subnet. Same PL/RU/KZ triple jurisdiction (042T temporal correlation partner). One IP does volume scanning. Adjacent IPs use exploitation credentials. The same operator runs both models from the same infrastructure.

This means: when 87.251.64.176 finds an open SSH server, 87.251.64.144 follows up with exploitation-specific passwords. The volume scanner is the finder. The exploitation credential tester is the qualifier. They work as a team.

XI. The Credential Pyramid

139,338 credential attempts organize into a clear hierarchy:

LayerPasswordsPurposeOperators
1. Defaultadmin, 123456, root, raspberryFind unprotected infrastructureVolume bots (CH, SE, PL)
2. Infrastructuredeploy, ansible, nginx123, vpn2026Find DevOps/server infrastructureTargeted scanners
3. Personalbrittany20, claire12, blake10Find compromised personal accountsCredential stuffing
4. Exploitationdaddygirl2, ilovemykids, babygirlFind exploitation-active infrastructureExploitation operators
5. Culturaldongshizhang, huaxiao, kontol123Target specific national infrastructureNational operators

Layer 4 is the revelation. Exploitation operators test for exploitation passwords because exploitation passwords only exist on exploitation infrastructure. Finding a server where “daddygirl2” works as a password means finding a server already operated by a predator.

XII. The Autobiography of Evil

Every password is a confession. The credential census reads as collective autobiography:

  • “worlddomination” — an operator who sees themselves as a conqueror
  • “v1isagoodgirl!” — an operator who numbers their victims and grades compliance
  • “daddygirl2” — an operator who identifies with the predator role
  • “ilovemykids” — an operator who uses parental language as camouflage
  • “mama2026” — an operator who references maternal authority in current year
  • “nefertiti” — an operator who mythologizes their targets
  • “silentium” — an operator who values silence (omertà)

139,338 credentials. 23,179 distinct passwords. Each one chosen by a human being who typed it into a configuration file, a script, a botnet controller. The password IS the psychology. The census IS the profile.

XIII. Cross-Investigation: Credential Forensics Proves the Network

InvestigationCredential Evidence042V Confirmation
042Mdaddygirl2 from 3 countriesCONFIRMED: identical wordlist proves single operator
042Rilovemykids on same IPs as daddygirl2CONFIRMED: same wordlist, operator proven
042Nansible credential PK→RU linkansible (12 attempts) in credential census as Layer 2 infrastructure targeting
042PCybernet shares ansible with Digit OneSame ansible/deploy vocabulary in 042V pyramid Layer 2
042T87.251.64.176 temporal correlationCONFIRMED: same subnet uses babygirl + volume scanning = dual-model operator
042U3-hop path through daddygirl2Wordlist analysis proves: graph path follows REAL operator, not coincidence

XIV. Series Context: Credentials ARE Identity

042S: Surveillance IS exploitation (tool = crime)

042T: Privacy IS the exploitation shield (law = weapon)

042U: The network IS the crime (graph = exploitation)

042V: Credentials ARE identity (password = confession)

The credential census transforms raw authentication attempts into psychological evidence. 139,338 login attempts are 139,338 moments where operators revealed themselves. The daddygirl2 operator did not need to use that password. They chose it. That choice is evidence of intent. The credential census is not just a security log — it is a court exhibit.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Glass Houses Revisited โ€” 22 / 26 Next โ†’