Every authentication attempt against one internet-facing honeypot over six days, with the password each one carried recovered where cracking succeeded.
Attempts
Passwords recovered
Source IPs
Usernames tried
Distinct passwords
Peak hour
Attempts per hour
117 hourly buckets across the capture window
Traffic runs at a low baseline for three days, then steps up by an order of magnitude on 23–24 August. That is a new operator arriving, not the existing ones speeding up.
Hour of day
All six days aggregated, UTC
A real diurnal cycle: 22:00–04:00 UTC carries 20× the traffic of 06:00–14:00. Earlier captures on this host were flat around the clock — this population is not.
Campaign shape
Each dot is one source IP — attempts against usernames tried (log scales)
Bottom-right is a grinder — thousands of guesses at one account. Top-left is an enumerator — few guesses across many accounts. The gap between them is why one blocklist never covers both.
Busiest sources
Top 15 of source addresses
Source IP
Attempts
Users
Most-targeted accounts
Top 12 of usernames
Username
Attempts
Most-guessed passwords
Recovered cleartext, ranked by how many separate attempts carried it
Password
Attempts
Password
Attempts
Reading these numbers. Each attempt is one credential guess captured at the NLA/CredSSP stage, so the password is recovered by cracking the NetNTLMv2 response rather than read directly. Roughly 91% resolved; the rest are shown as attempts without a password rather than dropped. Times are the honeypot’s own clock in UTC.