TI-2026-043C โ The Product Credential
When credential vocabulary applies product naming conventions to human beings.
"v1isagoodgirl!"
โ SSH credential captured from 5 IPs across 4 countries. Version 1 is a good girl. A software release note written about a person.I. The Anatomy of a Product Name
In software engineering, version numbering follows a convention: v1.0, v2.3.1, release-candidate-4. The prefix v means "version." The number means "iteration." The whole construct means: this is a thing we made, and we're counting how many times we've made it.
On our honeypot, we captured this credential from five different IP addresses across four countries:
This is not a password someone chose for their email account. This is not a default credential for a database server. This is not a common breach-list entry. In a corpus of 139,335 credentials, this term appears as a statistical outlier โ absent from RockYou, LinkedIn breach data, standard dictionary attacks, and common default password lists.
Someone โ deliberately โ put this into an automated credential dictionary. And then deployed it from infrastructure in multiple countries.
II. The Catalog
The v1isagoodgirl! credential does not exist alone. It belongs to a family of credentials that apply the same logic: product naming conventions applied to human beings.
Each of these credentials treats a human being as a thing:
-
daddygirl2 โ The
2suffix is iteration. Version 2 of a relationship between predator (daddy) and product (girl). The first version existed. This is the replacement. - eyecandy โ Commerce language. "Eye candy" = something attractive to look at. The person is reduced to visual commodity. A display item.
- ilovemykids โ Possessive. My kids. The pronoun claims ownership. Combined with daddygirl2 from the same IP, the "love" is predatory, not parental.
- kids123 โ Serialization. Kids + sequential numbering. Inventory management syntax applied to children.
- lady01, brittany20, claire12 โ Female names + serial numbers. Individual humans indexed by number. A database of people.
III. The Operator's Complete Wordlist
Through cross-correlation of credential attempts from the three daddygirl2 IPs (documented in TI-2026-042V), we have reconstructed the operator's complete custom wordlist โ 115+ passwords that constitute a psychological profile:
Reconstructed Wordlist โ Categorized
This is not a generic password dictionary. Generic dictionaries contain: admin, password, 123456, qwerty, letmein. They come from breach databases โ millions of real passwords that real people chose for real accounts.
This wordlist contains none of those. Instead, it contains:
- Child exploitation vocabulary โ daddygirl2, ilovemykids, kids123, babygirl, mama2026
- Female names with serial numbers โ brittany20, claire12, lady01, blake10 (people indexed as inventory)
- Chinese-language credentials โ huaxiao@Fire2026, 128@Wang!!, dongshizhang (indicating Chinese-speaking operator)
- Grandiose aspiration โ worlddomination (psychological signature: megalomania)
The psychology is transparent: an exploitation-motivated, Chinese-speaking operator who indexes victims by name+number and aspires to total control. The wordlist is the confession.
IV. The Network Map
This operator does not work from a single machine. The April 3, 2026 deployment event โ when the exploitation wordlist appeared simultaneously from three IPs across three countries โ proves centralized command and control.
| IP | Country | Provider | ASN | Credentials | Classification |
|---|---|---|---|---|---|
| 103.250.11.118 | ID | CloudHost | AS138608 | daddygirl2, eyecandy, ilovemykids, brittany20... | Primary |
| 138.128.240.172 | IL/US | Kamatera/OMC | AS36007 | daddygirl2, eyecandy, ilovemykids, brittany20... | Israeli Multi-ASN |
| 171.244.141.86 | VN | Viettel Group | AS7552 | daddygirl2, eyecandy, ilovemykids, mama2026... | Military |
| 103.250.11.156 | ID | CloudHost | AS138608 | v1isagoodgirl! | Same /16 |
| 45.66.131.134 | โ | TBD | โ | v1isagoodgirl! | v1 cluster |
| 103.189.208.13 | VN | TEDEV | โ | v1isagoodgirl! | v1 cluster |
| 103.210.21.97 | โ | TBD | โ | v1isagoodgirl! | v1 cluster |
| 197.199.224.52 | โ | TBD | โ | v1isagoodgirl! | v1 cluster |
| 103.166.103.173 | PK | Grand Tel | โ | Linked via OTX pulse | Telecom |
The /16 Subnet Connection
A critical detail: IP 103.250.11.156 (which uses v1isagoodgirl!) is in the same /16 subnet as 103.250.11.118 (which uses daddygirl2). The 103.250.x.x block belongs to CloudHost Indonesia. This means:
- โธ The daddygirl2 operator and the v1isagoodgirl operator share network infrastructure
- โธ Both apply product-naming conventions to humans (version numbers, serial numbers)
- โธ Both use CloudHost Indonesia as their hosting provider
- โธ This is likely the SAME operator or the same credential distribution network
V. The FBI Precedent
This is not the first time coded language has been documented in exploitation networks.
FBI Cyber Division โ Innocent Images National Initiative (January 31, 2007)
"Pedophiles, to include those who sexually abuse children as well as those who produce, distribute, and trade child pornography, are using various types of identification logos or symbols to recognize one another and distinguish their sexual preferences."
Documented symbols include: CLogo (Child Lover triangle), CLOMAL (Childlove Online Media Activism), and various coded identification phrases.
The credential daddygirl2 fits this documented pattern precisely: coded identification language that signals exploitation preference while appearing innocuous to automated systems.
The difference between 2007 and 2026 is the medium. In 2007, the coded language appeared in forum signatures, profile images, and chat handles. In 2026, it appears in SSH credential dictionaries deployed from enterprise cloud infrastructure. The vocabulary migrated from social platforms to technical infrastructure โ where it is even harder to detect, because credential dictionaries are never reviewed for content.
VI. The Grooming Mirror
From the Epstein Files depositions (EFTA00008631, under oath):
"Usually when the grooming happens, an offender will โ once they gain that trust, they will make the relationship turn sexual."
โ Expert testimony, Epstein civil proceedingsGrooming uses terms of endearment to establish a relationship before exploitation: princess, angel, babygirl, kitten, sweetheart. These are the exact words used by predators to normalize a power dynamic โ making the victim feel "special" and "chosen."
Now look at the honeypot credential corpus:
These are not accidental. In a corpus of 139,335 credentials dominated by admin, root, password, and 123456, the presence of grooming vocabulary is a statistical anomaly that requires explanation. The explanation provided by the data is: someone with knowledge of grooming terminology deliberately included it in automated credential dictionaries.
VII. The Food Code Convergence
Previous dossier TI-2026-040F ("The Food Code") documented that law enforcement has identified food terminology as coded commerce language for exploitation. Our honeypot shows this vocabulary converging with the product credentials in the same dictionaries:
Single-Dictionary Convergence (Proven: Same IPs)
The Kenya-Panama-Ecuador triangle (IPs 41.139.202.227, 181.78.121.148, 177.234.209.102) uses all three: banana666 (food code + satanic number), cart00ns (leet-speak children's media), and warnightkardesim (Turkish nationalist botnet). One operator. One dictionary. Three continents. Five vocabulary categories converging.
This is not a coincidence. These are not separate phenomena accidentally sharing infrastructure. The same operators who use explicit exploitation language also use coded commerce language also use children's media references. They converge because they serve the same function: different encoding layers for the same operation.
VIII. The Geographic Signal
Poland emerges repeatedly in this analysis:
- 48 exploitation-related credential attempts from Polish IPs (documented TI-2026-042L)
- ISAEV Igor (Kazakhstan) operates 4 Polish IPs for credential stuffing (87.251.64.144-149)
- Poland represents 0.5% of global internet but carries disproportionate exploitation vocabulary
Poland as a hosting jurisdiction offers: EU legal framework (complicating takedown requests from non-EU countries), relatively low hosting costs, geographic proximity to both Western European markets and Eastern European operators, and historically permissive hosting environments. This makes it an attractive location for bulletproof hosting operations โ infrastructure designed specifically to resist takedown.
The Pakistan-Israel Pipeline
Grand Tel Pakistan (103.166.103.173) shares an OTX threat intelligence pulse with Kamatera Israel โ the same Kamatera IP (138.128.240.172) that carries the daddygirl2 credential. This connection means the Pakistani telecom and the Israeli hosting provider appeared in the same documented attack campaign. A pipeline exists between Pakistan and Israel carrying exploitation credentials.
IX. The April 3 Event
The simultaneity proves centralized command. Someone, on April 3, 2026, issued an update to a botnet. That update contained child exploitation vocabulary. It was received and executed by infrastructure in three countries. This is an operation, not a random occurrence.
X. What This Means
The "product credential" pattern reveals something specific about the operators behind these dictionaries:
1. They think in inventory. v1isagoodgirl! is versioning. brittany20 is indexing. kids123 is serialization. These are the cognitive patterns of someone who manages stock โ who thinks of people as items in a catalog.
2. They mix operational languages. Chinese credentials (huaxiao@Fire2026, dongshizhang) alongside English exploitation terms (daddygirl2, eyecandy) indicate a bilingual operator working across linguistic boundaries. This is consistent with transnational trafficking operations that span Chinese-speaking and English-speaking markets.
3. They deploy at scale. The April 3 simultaneous push across three countries is not a hobby operation. This is infrastructure. This is investment. Three cloud hosting accounts across three jurisdictions costs money and requires coordination.
4. They leave breadcrumbs by design. The wordlist IS the operator's identity. Unlike generic dictionaries that are shared by millions, a custom wordlist with 115 specific passwords โ including names, Chinese phrases, and exploitation terms โ is a fingerprint. This operator can be tracked across any infrastructure that receives their dictionary update.
XI. The Statistical Argument
Some will argue: these are just passwords. People choose all kinds of passwords. "daddygirl" could be a teenager's password for her social media account.
The statistical response:
Why the "innocent password" argument fails
- Distribution pattern: Personal passwords appear from ONE IP (the person's device). These appear from 3-5 IPs across multiple countries simultaneously.
- Co-occurrence: A teenager's password would not appear alongside huaxiao@Fire2026 and dongshizhang in the same list from the same IP.
- Deployment timing: Personal passwords don't appear simultaneously on April 3 from three continents.
- Absence from breach databases: If daddygirl2 were a common personal password, it would appear in RockYou (32M passwords) or LinkedIn (117M passwords). It does not.
- Credential family: A teenager would not also use kids123, ilovemykids, lady01, and worlddomination from the same IP address.
- Statistical outlier: In 139,335 credentials, exploitation terms are anomalous. They don't match ANY standard password distribution pattern.
XII. What This Does Not Prove
Epistemic Boundaries
This investigation does not prove that the daddygirl2 operator is actively trafficking children. We observe:
- A custom wordlist containing exploitation vocabulary
- Deployment from 3 countries via cloud infrastructure
- Coordination (April 3 simultaneous push)
- Co-occurrence with food codes and children's media references
- Statistical anomaly in a 139K credential corpus
We do not observe: actual trafficking activity, victim identification, transaction records, or direct communication. What we observe is that someone with exploitation-specific vocabulary has invested in multi-country infrastructure to deploy that vocabulary at scale. The investment and coordination are real. The intent behind them requires further investigation.
XIII. What This Does Prove
1. Product naming conventions are applied to humans in operational credential dictionaries. v1isagoodgirl, brittany20, kids123 โ these follow inventory management syntax. This is documented, timestamped, and multi-sourced.
2. The vocabulary is NOT generic โ it is CURATED. Absence from standard breach databases + absence from default password lists + presence only in custom dictionaries = deliberate inclusion by operators familiar with exploitation language.
3. A single operator manages a multi-country exploitation credential network. Identical wordlists from Indonesia, Israel, and Vietnam, deployed simultaneously April 3, 2026. One controller, three jurisdictions, custom exploitation dictionary.
4. The credential IS the operator's fingerprint. A 115-password custom list with Chinese credentials, female names+numbers, child exploitation terms, and "worlddomination" is unique enough to track across any infrastructure that receives it.
5. Exploitation vocabulary converges with food codes and children's media in SAME dictionaries. Not separate phenomena โ same operators, same dictionaries, same infrastructure. The encoding layers serve the same function.
XIV. The Product
A credential dictionary is a list of things an operator believes might be true. When that list contains "v1isagoodgirl!" it reveals what the operator believes exists in the world: versioned humans, graded for compliance, categorized by gender and age.
The credential is not trying to access a server. The server is not the target. The server is the vector. The credential list is the operator's worldview โ and in that worldview, girls have version numbers.
โ Next: TI-2026-043D โ The Theological Credential