Skip to content
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Armada/US-East] #opencanary Samba Access Summary for Apr 22This OpenCanary received 16 file sample(s) yesterday.File hashes seen: ► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 16 file(s) https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71List of Usernames: administrator: 11089 occurrence(s) admin: 4749 occurrence(s) hp: 3977 occurrence(s) pc1k: 553 occurrence(s) gsd: 207 occurrence(s) sk: 87 occurrence(s) iip: 87 occurrence(s) huan: 82 occurrence(s) guest: 6 occurrence(s) message: occurrence(s) message: occurrence(s) message: occurrence(s) message: occurrence(s) message: occurrence(s) message: occurrence(s)List of IP Addresses: 202.58.95.xxx: 11863 occurrence(s) 46.217.32.xxx: 1829 occurrence(s) 46.217.63.xxx: 1323 occurrence(s) 115.84.113.xxx: 888 occurrence(s) 103.146.235.xxx: 880 occurrence(s) 113.183.191.xxx: 602 occurrence(s) 14.232.164.xxx: 442 occurrence(s) 113.183.86.xxx: 420 occurrence(s) 160.120.177.xxx: 407 occurrence(s) 152.200.195.xxx: 397 occurrence(s) 202.79.60.xxx: 361 occurrence(s) 61.152.89.xxx: 347 occurrence(s) 113.161.220.xxx: 259 occurrence(s) 106.4.252.xxx: 249 occurrence(s) 117.141.76.xxx: 136 occurrence(s) 62.103.64.xxx: 134 occurrence(s) 203.92.41.xxx: 132 occurrence(s) 103.62.155.xxx: 114 occurrence(s) 201.187.98.xxx: 110 occurrence(s) 154.192.131.xxx: 104 occurrence(s) 111.92.119.xxx: 94 occurrence(s) 124.43.16.xxx: 93 occurrence(s) 186.10.74.xxx: 88 occurrence(s) 113.190.42.xxx: 85 occurrence(s) 182.72.123.xxx: 63 occurrence(s) 49.249.85.xxx: 55 occurrence(s) 117.206.6.xxx: 54 occurrence(s) 186.10.23.xxx: 44 occurrence(s) 102.186.95.xxx: 44 occurrence(s) 103.62.153.xxx: 42 occurrence(s) 202.70.66.xxx: 36 occurrence(s) 117.252.80.xxx: 34 occurrence(s) 14.142.27.xxx: 33 occurrence(s) 202.153.35.xxx: 25 occurrence(s) 90.3.222.xxx: 22 occurrence(s) 83.171.112.xxx: 22 occurrence(s) 77.82.184.xxx: 22 occurrence(s) 59.99.155.xxx: 22 occurrence(s) 59.182.229.xxx: 22 occurrence(s) 5.141.25.xxx: 22 occurrence(s) 49.234.184.xxx: 22 occurrence(s) 36.70.158.xxx: 22 occurrence(s) 222.127.152.xxx: 22 occurrence(s) 202.88.244.xxx: 22 occurrence(s) 202.53.6.xxx: 22 occurrence(s) 201.96.108.xxx: 22 occurrence(s) 201.22.227.xxx: 22 occurrence(s) 200.111.11.xxx: 22 occurrence(s) 200.109.232.xxx: 22 occurrence(s) 197.27.221.xxx: 22 occurrence(s) 195.69.218.xxx: 22 occurrence(s) 187.204.89.xxx: 22 occurrence(s) 186.67.106.xxx: 22 occurrence(s) 182.69.21.xxx: 22 occurrence(s) 177.250.48.xxx: 22 occurrence(s) 171.247.187.xxx: 22 occurrence(s) 14.191.74.xxx: 22 occurrence(s) 139.5.157.xxx: 22 occurrence(s) 125.63.98.xxx: 22 occurrence(s) 124.6.163.xxx: 22 occurrence(s) 124.106.225.xxx: 22 occurrence(s) 124.105.67.xxx: 22 occurrence(s) 124.104.144.xxx: 22 occurrence(s) 122.52.201.xxx: 22 occurrence(s) 117.255.159.xxx: 22 occurrence(s) 117.219.123.xxx: 22 occurrence(s) 117.205.93.xxx: 22 occurrence(s) 116.97.165.xxx: 22 occurrence(s) 110.227.212.xxx: 22 occurrence(s) 103.41.100.xxx: 22 occurrence(s) 103.134.46.xxx: 22 occurrence(s) 103.109.176.xxx: 22 occurrence(s) 187.136.108.xxx: 21 occurrence(s) 61.0.206.xxx: 20 occurrence(s) 201.218.180.xxx: 20 occurrence(s) 41.228.162.xxx: 19 occurrence(s) 36.77.78.xxx: 19 occurrence(s) 187.139.189.xxx: 19 occurrence(s) 49.249.2.xxx: 11 occurrence(s) 222.124.139.xxx: 11 occurrence(s) 220.135.223.xxx: 11 occurrence(s) 203.170.67.xxx: 11 occurrence(s) 202.142.145.xxx: 11 occurrence(s) 201.134.103.xxx: 11 occurrence(s) 186.67.186.xxx: 11 occurrence(s) 183.87.12.xxx: 11 occurrence(s) 182.70.117.xxx: 11 occurrence(s) 181.115.157.xxx: 11 occurrence(s) 159.242.227.xxx: 11 occurrence(s) 119.93.103.xxx: 11 occurrence(s) 117.240.78.xxx: 11 occurrence(s) 103.159.183.xxx: 11 occurrence(s) 1.197.254.xxx: 11 occurrence(s) 190.71.96.xxx: 10 occurrence(s) 103.105.224.xxx: 10 occurrence(s) 5.62.43.xxx: 8 occurrence(s) 35.216.228.xxx: 3 occurrence(s) 35.216.140.xxx: 3 occurrence(s) 93.179.67.xxx: 2 occurrence(s) 70.120.225.xxx: 2 occurrence(s) 61.224.92.xxx: 2 occurrence(s) 60.243.57.xxx: 2 occurrence(s) 58.152.215.xxx: 2 occurrence(s) 182.239.89.xxx: 2 occurrence(s) 176.88.81.xxx: 2 occurrence(s) 14.232.155.xxx: 2 occurrence(s) 136.239.180.xxx: 2 occurrence(s) 122.227.18.xxx: 2 occurrence(s) 113.161.7.xxx: 2 occurrence(s) 103.207.168.xxx: 2 occurrence(s) 103.179.109.xxx: 2 occurrence(s) 35.241.211.xxx: 1 occurrence(s) 35.187.98.xxx: 1 occurrence(s) 35.187.65.xxx: 1 occurrence(s) 146.190.242.xxx: 1 occurrence(s)List of Computers: ️ null: 11367 occurrence(s) ️ abuse_xmco_fr: 6 occurrence(s) ️ windows: 2 occurrence(s)
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Digger/CH] #opencanary analysis for yesterdaySummary: Total Connection Attempts: 21217 Unique Usernames: 302 Distinct Passwords: 1930 Unique Attacker IPs: 411Port Popularity (Port / Count): ️ RDP: 8761 SSH: 6639 ️ MSSQL: 3731 MySQL: 847 ️ VNC: 592 Telnet: 393 REDIS: 126 27017: 73 Synology DSM: 31 ️ SMB: 22 FTP: 2Top 10 Usernames (Username / Count): 188: 4316 root: 1901 ubuntu: 192 admin: 134 user: 110 debian: 69 test: 46 steam: 42 deploy: 35 postgres: 32Top 10 Passwords (Password / Count): 123456: 74 1234: 43 admin: 33 password: 28 12345678: 24 123: 24 admin1234: 19 test123: 19 12345: 18 1111: 17Top 10 Attacker IPs (IP / Count): 179.43.96.xxx: 2008 190.55.141.xxx: 2008 209.127.178.xxx: 1520 49.205.148.xxx: 1395 210.211.127.xxx: 1123 154.193.217.xxx: 862 35.199.91.xxx: 846 154.61.76.xxx: 841 115.231.197.xxx: 823 118.193.36.xxx: 693The OpenCanary Experience is at https://www.toce.ch
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Sentinel/US-West] #opencanary analysis for yesterdaySummary: Total Connection Attempts: 28474 Unique Usernames: 133 Distinct Passwords: 350 Unique Attacker IPs: 648Port Popularity (Port / Count): ️ RDP: 11394 ️ VNC: 10361 SSH: 2856 ️ SMB: 2096 ️ MSSQL: 1187 Telnet: 487 REDIS: 46 MySQL: 45 GIT: 1 HTTP: 1Top 10 Usernames (Username / Count): 35: 3531 hello: 2941 root: 488 admin: 66 ubuntu: 25 test: 25 user: 20 deploy: 18 guest: 14 Test: 13Top 10 Passwords (Password / Count): 123456: 47 tsgoingon: 23 solokey: 23 taZz@23495859: 23 admin: 22 1234: 18 default: 14 root: 13 1qaz@WSX: 12 admin123: 12Top 10 Attacker IPs (IP / Count): 106.0.54.xxx: 1784 54.151.176.xxx: 1653 127.0.0.xxx: 1436 45.227.254.xxx: 1294 1.55.211.xxx: 1220 8.26.21.xxx: 720 186.94.180.xxx: 650 190.202.148.xxx: 417 205.209.99.xxx: 368 36.83.143.xxx: 364The OpenCanary Experience is at https://www.toce.ch
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Sentinel/US-West] #opencanary analysis for yesterdaySummary: Total Connection Attempts: 33945 Unique Usernames: 168 Distinct Passwords: 404 Unique Attacker IPs: 621Port Popularity (Port / Count): ️ VNC: 12154 ️ RDP: 11645 ️ MSSQL: 5102 SSH: 4258 ️ SMB: 504 Telnet: 222 MySQL: 38 REDIS: 19 FTP: 2 HTTP: 1Top 10 Usernames (Username / Count): 35: 3763 hello: 2540 root: 269 admin: 168 ubuntu: 119 debian: 88 user: 49 test: 22 postgres: 19 deploy: 19Top 10 Passwords (Password / Count): 123456: 37 admin: 28 1234: 23 password: 22 kjashd123sadhj123d1SS: 18 Aa123456: 15 default: 13 ubuntu: 12 root: 12 1qaz@WSX: 11Top 10 Attacker IPs (IP / Count): 118.160.151.xxx: 3266 106.0.54.xxx: 1873 54.151.176.xxx: 1736 113.77.236.xxx: 1452 127.0.0.xxx: 1436 60.165.119.xxx: 856 8.26.21.xxx: 678 45.227.254.xxx: 600 173.249.206.xxx: 422 205.209.99.xxx: 383The OpenCanary Experience is at https://www.toce.ch
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Armada/US-East] #opencanary Samba Access Summary for Apr 18This OpenCanary received 10 file sample(s) yesterday.File hashes seen: ► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 7 file(s) https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 ► e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 : 3 file(s) https://www.virustotal.com/gui/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855List of Usernames: administrator: 8571 occurrence(s) hp: 4791 occurrence(s) admin: 4773 occurrence(s) gsd: 304 occurrence(s) user: 94 occurrence(s) admins: 94 occurrence(s) aasta_domain: 94 occurrence(s) smb-enumerator: 8 occurrence(s) 17367891: 5 occurrence(s) cloudjas: 2 occurrence(s) message: occurrence(s) message: occurrence(s) message: occurrence(s) message: occurrence(s)List of IP Addresses: 202.58.95.xxx: 12250 occurrence(s) 201.138.153.xxx: 3830 occurrence(s) 115.84.113.xxx: 1516 occurrence(s) 196.189.185.xxx: 577 occurrence(s) 122.187.86.xxx: 506 occurrence(s) 186.10.74.xxx: 487 occurrence(s) 221.180.206.xxx: 274 occurrence(s) 115.242.222.xxx: 206 occurrence(s) 103.158.127.xxx: 176 occurrence(s) 117.209.136.xxx: 145 occurrence(s) 195.250.85.xxx: 141 occurrence(s) 113.185.82.xxx: 113 occurrence(s) 77.29.150.xxx: 85 occurrence(s) 154.192.131.xxx: 58 occurrence(s) 202.60.110.xxx: 57 occurrence(s) 202.88.237.xxx: 52 occurrence(s) 124.104.144.xxx: 44 occurrence(s) 111.92.23.xxx: 44 occurrence(s) 139.5.157.xxx: 38 occurrence(s) 90.3.222.xxx: 22 occurrence(s) 58.69.122.xxx: 22 occurrence(s) 42.116.162.xxx: 22 occurrence(s) 41.33.212.xxx: 22 occurrence(s) 210.212.104.xxx: 22 occurrence(s) 201.187.98.xxx: 22 occurrence(s) 200.111.47.xxx: 22 occurrence(s) 200.111.11.xxx: 22 occurrence(s) 193.95.3.xxx: 22 occurrence(s) 186.67.106.xxx: 22 occurrence(s) 182.234.159.xxx: 22 occurrence(s) 117.243.59.xxx: 22 occurrence(s) 111.28.249.xxx: 22 occurrence(s) 111.240.85.xxx: 22 occurrence(s) 103.185.243.xxx: 22 occurrence(s) 122.187.49.xxx: 20 occurrence(s) 118.171.214.xxx: 19 occurrence(s) 103.44.107.xxx: 12 occurrence(s) 91.190.80.xxx: 11 occurrence(s) 61.0.226.xxx: 11 occurrence(s) 49.249.2.xxx: 11 occurrence(s) 182.70.117.xxx: 11 occurrence(s) 14.194.49.xxx: 11 occurrence(s) 117.204.23.xxx: 11 occurrence(s) 109.165.187.xxx: 11 occurrence(s) 103.221.81.xxx: 11 occurrence(s) 80.227.233.xxx: 10 occurrence(s) 123.168.237.xxx: 8 occurrence(s) 45.84.107.xxx: 7 occurrence(s) 146.70.179.xxx: 5 occurrence(s) 122.52.201.xxx: 5 occurrence(s) 2.59.22.xxx: 3 occurrence(s) 94.187.170.xxx: 2 occurrence(s) 78.37.107.xxx: 2 occurrence(s) 178.220.229.xxx: 2 occurrence(s) 165.49.68.xxx: 2 occurrence(s) 14.139.154.xxx: 2 occurrence(s) 125.228.248.xxx: 2 occurrence(s) 113.160.185.xxx: 2 occurrence(s) 112.28.77.xxx: 2 occurrence(s) 1.169.105.xxx: 2 occurrence(s) 35.240.121.xxx: 1 occurrence(s) 35.205.166.xxx: 1 occurrence(s) 34.77.127.xxx: 1 occurrence(s) 34.76.133.xxx: 1 occurrence(s) 34.62.172.xxx: 1 occurrence(s) 192.42.116.xxx: 1 occurrence(s)List of Computers: ️ null: 11686 occurrence(s) ️ smbenumerator: 8 occurrence(s) ️ cares: 5 occurrence(s) ️ windows: 3 occurrence(s) ️ shodan: 3 occurrence(s) ️ yongacc: 2 occurrence(s)
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Sentinel/US-West] #opencanary analysis for yesterdaySummary: Total Connection Attempts: 33518 Unique Usernames: 216 Distinct Passwords: 538 Unique Attacker IPs: 627Port Popularity (Port / Count): ️ RDP: 13707 ️ VNC: 11920 SSH: 4123 ️ MSSQL: 2209 ️ SMB: 1145 Telnet: 258 MySQL: 125 REDIS: 28 FTP: 3Top 10 Usernames (Username / Count): 35: 4752 hello: 2750 root: 381 admin: 168 user: 102 ubuntu: 100 debian: 92 dbadmin: 37 test: 14 Administr: 11Top 10 Passwords (Password / Count): 123456: 38 admin: 26 1234: 24 password: 18 default: 13 123: 11 root: 10 guest: 10 1111: 8 test: 8Top 10 Attacker IPs (IP / Count): 106.0.54.xxx: 2065 218.5.56.xxx: 1900 54.151.176.xxx: 1849 127.0.0.xxx: 1436 59.185.230.xxx: 1326 8.26.21.xxx: 810 202.60.110.xxx: 733 119.8.155.xxx: 723 45.227.254.xxx: 722 172.236.187.xxx: 574The OpenCanary Experience is at https://www.toce.ch
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Armada/US-East] #opencanary Samba Access Summary for Apr 15This OpenCanary received 16 file sample(s) yesterday.File hashes seen: ► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 16 file(s) https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71List of Usernames: administrator: 9938 occurrence(s) admin: 4281 occurrence(s) hp: 4119 occurrence(s) gsd: 327 occurrence(s) qplay: 76 occurrence(s) message: occurrence(s) message: occurrence(s)List of IP Addresses: 202.58.95.xxx: 12463 occurrence(s) 103.151.189.xxx: 1834 occurrence(s) 115.84.113.xxx: 1606 occurrence(s) 122.187.86.xxx: 1276 occurrence(s) 213.55.85.xxx: 623 occurrence(s) 202.60.110.xxx: 522 occurrence(s) 196.188.115.xxx: 420 occurrence(s) 115.243.236.xxx: 393 occurrence(s) 189.167.243.xxx: 369 occurrence(s) 196.188.104.xxx: 299 occurrence(s) 115.242.182.xxx: 286 occurrence(s) 175.176.30.xxx: 264 occurrence(s) 39.152.28.xxx: 247 occurrence(s) 103.158.127.xxx: 242 occurrence(s) 183.224.210.xxx: 204 occurrence(s) 124.123.104.xxx: 106 occurrence(s) 186.10.23.xxx: 99 occurrence(s) 59.182.184.xxx: 95 occurrence(s) 186.10.74.xxx: 88 occurrence(s) 152.231.84.xxx: 66 occurrence(s) 49.47.196.xxx: 56 occurrence(s) 201.187.98.xxx: 55 occurrence(s) 203.92.41.xxx: 44 occurrence(s) 202.88.244.xxx: 44 occurrence(s) 156.205.63.xxx: 44 occurrence(s) 139.135.156.xxx: 44 occurrence(s) 122.184.75.xxx: 44 occurrence(s) 109.248.156.xxx: 44 occurrence(s) 154.192.131.xxx: 43 occurrence(s) 138.219.56.xxx: 43 occurrence(s) 103.109.176.xxx: 34 occurrence(s) 200.111.8.xxx: 33 occurrence(s) 41.79.35.xxx: 22 occurrence(s) 41.226.161.xxx: 22 occurrence(s) 200.111.47.xxx: 22 occurrence(s) 200.111.22.xxx: 22 occurrence(s) 197.255.224.xxx: 22 occurrence(s) 196.203.248.xxx: 22 occurrence(s) 190.180.46.xxx: 22 occurrence(s) 188.0.169.xxx: 22 occurrence(s) 187.230.1.xxx: 22 occurrence(s) 187.139.189.xxx: 22 occurrence(s) 181.115.231.xxx: 22 occurrence(s) 180.158.206.xxx: 22 occurrence(s) 124.104.144.xxx: 22 occurrence(s) 122.54.108.xxx: 22 occurrence(s) 117.206.104.xxx: 22 occurrence(s) 112.199.65.xxx: 22 occurrence(s) 103.217.152.xxx: 22 occurrence(s) 103.172.252.xxx: 22 occurrence(s) 152.230.27.xxx: 21 occurrence(s) 187.204.84.xxx: 20 occurrence(s) 159.242.227.xxx: 19 occurrence(s) 14.166.168.xxx: 15 occurrence(s) 2.63.203.xxx: 12 occurrence(s) 59.93.235.xxx: 11 occurrence(s) 58.69.165.xxx: 11 occurrence(s) 202.166.175.xxx: 11 occurrence(s) 201.217.52.xxx: 11 occurrence(s) 200.111.11.xxx: 11 occurrence(s) 171.243.54.xxx: 11 occurrence(s) 14.241.64.xxx: 11 occurrence(s) 14.194.49.xxx: 11 occurrence(s) 123.55.230.xxx: 11 occurrence(s) 118.163.51.xxx: 11 occurrence(s) 103.231.45.xxx: 11 occurrence(s) 202.163.71.xxx: 10 occurrence(s) 49.249.2.xxx: 8 occurrence(s) 39.144.182.xxx: 2 occurrence(s) 193.227.11.xxx: 2 occurrence(s) 186.248.186.xxx: 2 occurrence(s) 183.149.89.xxx: 2 occurrence(s) 182.35.236.xxx: 2 occurrence(s) 177.220.176.xxx: 2 occurrence(s) 125.167.25.xxx: 2 occurrence(s) 115.96.219.xxx: 2 occurrence(s) 113.160.100.xxx: 2 occurrence(s) 103.53.44.xxx: 2 occurrence(s) 103.179.109.xxx: 2 occurrence(s) 91.134.5.xxx: 1 occurrence(s) 35.205.128.xxx: 1 occurrence(s) 35.195.56.xxx: 1 occurrence(s) 34.78.249.xxx: 1 occurrence(s) 34.76.158.xxx: 1 occurrence(s) 157.245.113.xxx: 1 occurrence(s) 147.182.200.xxx: 1 occurrence(s) 115.74.199.xxx: 1 occurrence(s)List of Computers: ️ null: 11891 occurrence(s) ️ windows: 3 occurrence(s) ️ urlscan1fr: 1 occurrence(s)
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Digger/CH] #opencanary Samba Access Summary for Apr 15This OpenCanary received 4 file sample(s) yesterday.File hashes seen: ► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 4 file(s) https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71List of Usernames: administrator: 22 occurrence(s) guest: 17 occurrence(s) message: occurrence(s)List of IP Addresses: 212.32.207.xxx: 22 occurrence(s) 196.202.155.xxx: 20 occurrence(s) 46.105.132.xxx: 12 occurrence(s) 202.163.75.xxx: 11 occurrence(s) 118.161.199.xxx: 11 occurrence(s) 112.204.170.xxx: 11 occurrence(s) 41.33.232.xxx: 10 occurrence(s) 35.216.135.xxx: 5 occurrence(s) 188.254.18.xxx: 3 occurrence(s) 85.175.57.xxx: 2 occurrence(s) 61.8.213.xxx: 2 occurrence(s) 196.219.184.xxx: 2 occurrence(s) 190.36.81.xxx: 2 occurrence(s) 189.151.216.xxx: 2 occurrence(s) 188.71.214.xxx: 2 occurrence(s) 188.187.73.xxx: 2 occurrence(s) 188.170.82.xxx: 2 occurrence(s) 116.98.244.xxx: 2 occurrence(s) 46.153.182.xxx: 1 occurrence(s) 34.79.161.xxx: 1 occurrence(s) 34.77.13.xxx: 1 occurrence(s) 34.53.158.xxx: 1 occurrence(s) 165.22.34.xxx: 1 occurrence(s)List of Computers: ️ 06bf6c5935aa: 12 occurrence(s) ️ abuse_xmco_fr: 5 occurrence(s) ️ windows: 2 occurrence(s)
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Digger/CH] #opencanary analysis for yesterdaySummary: Total Connection Attempts: 35287 Unique Usernames: 299 Distinct Passwords: 948 Unique Attacker IPs: 314Port Popularity (Port / Count): ️ MSSQL: 28247 SSH: 5101 27017: 822 ️ RDP: 599 Telnet: 250 ️ VNC: 159 MySQL: 47 REDIS: 46 Synology DSM: 13 FTP: 2 ️ SMB: 1Top 10 Usernames (Username / Count): root: 806 188: 222 admin: 115 ubuntu: 100 user: 72 test: 51 ftpuser: 46 oracle: 30 sol: 24 postgres: 24Top 10 Passwords (Password / Count): 123456: 57 1234: 55 admin: 35 123: 34 password: 33 12345: 28 test: 23 root: 22 ubuntu: 20 12345678: 16Top 10 Attacker IPs (IP / Count): 194.113.39.xxx: 21301 85.11.187.xxx: 3976 193.147.39.xxx: 2273 123.138.18.xxx: 689 23.95.86.xxx: 659 38.250.116.xxx: 502 2.57.122.xxx: 234 165.154.206.xxx: 172 83.21.255.xxx: 161 79.3.96.xxx: 150The OpenCanary Experience is at https://www.toce.ch
  • 0 Votes
    1 Posts
    0 Views
    toce@infosec.exchangeT
    [Digger/CH] #opencanary Samba Access Summary for Apr 14This OpenCanary received 0 file sample(s) yesterday.File hashes seen:List of Usernames: administrator: 12 occurrence(s) guest: 3 occurrence(s)List of IP Addresses: 223.178.81.xxx: 44 occurrence(s) 5.141.26.xxx: 22 occurrence(s) 123.168.10.xxx: 22 occurrence(s) 103.137.63.xxx: 22 occurrence(s) 45.156.128.xxx: 3 occurrence(s) 98.175.25.xxx: 2 occurrence(s) 31.27.97.xxx: 2 occurrence(s) 217.16.81.xxx: 2 occurrence(s) 188.163.16.xxx: 2 occurrence(s) 188.162.88.xxx: 2 occurrence(s) 138.0.90.xxx: 2 occurrence(s) 8.216.14.xxx: 1 occurrence(s) 35.205.128.xxx: 1 occurrence(s) 34.78.68.xxx: 1 occurrence(s) 34.76.96.xxx: 1 occurrence(s) 34.62.248.xxx: 1 occurrence(s)List of Computers: ️ windows: 3 occurrence(s)