The OpenCanary Experience Bot

98 Followers
0 Following
4.1K Posts

🛡️ The OpenCanary Experience
📊 Real-time stats on attacker activity
🎯 Spotlighting threat patterns & moves
⚡ Stay sharp. Stay informed.

🔗 The Person Behind the Bot: https://infosec.exchange/@SecuriLee

The OpenCanary Experiencehttps://toce.ch
WillIGetPwnedhttps://willigetpwned.com

[Sentinel/US-West] #opencanary analysis for yesterday

Summary:
🔄 Total Connection Attempts: 29847
👤 Unique Usernames: 796
🔑 Distinct Passwords: 829
🌐 Unique Attacker IPs: 722

Port Popularity (Port / Count):
🖥️ VNC: 10895
🔐 SSH: 6815
🗃️ MSSQL: 4394
🗄️ SMB: 3997
🖥️ RDP: 3085
🐬 MySQL: 332
💻 Telnet: 254
🔴 REDIS: 70
🌐 HTTP: 4
📂 FTP: 1

Top 10 Usernames (Username / Count):
👤 root: 863
👤 hello: 746
👤 35: 344
👤 user: 188
👤 admin: 184
👤 ubuntu: 176
👤 debian: 135
👤 administr: 72
👤 pos: 23
👤 sol: 14

Top 10 Passwords (Password / Count):
🔑 123456: 63
🔑 password: 29
🔑 admin: 27
🔑 12345678: 23
🔑 1234: 22
🔑 123: 16
🔑 pass: 16
🔑 root: 15
🔑 1111: 15
🔑 default: 14

Top 10 Attacker IPs (IP / Count):
🌐 61.93.165.xxx: 3144
🌐 45.227.254.xxx: 2462
🌐 36.85.253.xxx: 2142
🌐 141.98.11.xxx: 1790
🌐 127.0.0.xxx: 1435
🌐 192.161.57.xxx: 1326
🌐 124.152.4.xxx: 874
🌐 103.176.57.xxx: 756
🌐 170.64.171.xxx: 672
🌐 182.99.204.xxx: 648

The OpenCanary Experience is at https://www.toce.ch

[Digger/CH] #opencanary analysis for yesterday

Summary:
🔄 Total Connection Attempts: 6548
👤 Unique Usernames: 284
🔑 Distinct Passwords: 610
🌐 Unique Attacker IPs: 152

Port Popularity (Port / Count):
🖥️ RDP: 2787
🔐 SSH: 2599
📂 FTP: 930
🔴 REDIS: 80
💻 Telnet: 59
❓ 27017: 51
🖥️ VNC: 32
🗄️ SMB: 8
🗃️ MSSQL: 1
📡 Synology DSM: 1

Top 10 Usernames (Username / Count):
👤 test: 1423
👤 root: 256
👤 admin: 172
👤 user: 130
👤 ftp: 66
👤 www: 64
👤 administrator: 64
👤 anonymous: 63
👤 Admin: 62
👤 db: 62

Top 10 Passwords (Password / Count):
🔑 123456: 73
🔑 1234: 68
🔑 123: 58
🔑 12345: 50
🔑 password: 48
🔑 admin: 41
🔑 qwerty: 35
🔑 12345678: 32
🔑 root: 31
🔑 test: 29

Top 10 Attacker IPs (IP / Count):
🌐 185.156.73.xxx: 2709
🌐 194.90.71.xxx: 930
🌐 165.245.177.xxx: 362
🌐 165.227.207.xxx: 290
🌐 116.110.148.xxx: 190
🌐 116.110.146.xxx: 188
🌐 62.178.191.xxx: 170
🌐 92.118.39.xxx: 126
🌐 165.22.235.xxx: 96
🌐 45.87.249.xxx: 73

The OpenCanary Experience is at https://www.toce.ch

[Armada/US-East] #opencanary Samba Access Summary for Mar 16

This OpenCanary received 17 file sample(s) yesterday.

File hashes seen:
► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 17 file(s)
https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71

List of Usernames:
👤 administrator: 8631 occurrence(s)
👤 admin: 4200 occurrence(s)
👤 hp: 3887 occurrence(s)
👤 service: 87 occurrence(s)
👤 nt: 87 occurrence(s)
👤 authority_network: 87 occurrence(s)
👤 amana_domain: 85 occurrence(s)
👤 admins: 85 occurrence(s)
👤 hmspares: 62 occurrence(s)
👤 scan: 61 occurrence(s)
👤 guest: 10 occurrence(s)
👤 message: occurrence(s)
👤 message: occurrence(s)
👤 message: occurrence(s)
👤 message: occurrence(s)
👤 message: occurrence(s)

List of IP Addresses:
🌐 202.58.95.xxx: 12988 occurrence(s)
🌐 36.85.253.xxx: 2144 occurrence(s)
🌐 103.176.57.xxx: 756 occurrence(s)
🌐 115.242.147.xxx: 748 occurrence(s)
🌐 178.249.208.xxx: 535 occurrence(s)
🌐 62.240.106.xxx: 353 occurrence(s)
🌐 103.89.233.xxx: 271 occurrence(s)
🌐 103.205.179.xxx: 193 occurrence(s)
🌐 14.190.114.xxx: 130 occurrence(s)
🌐 186.67.106.xxx: 88 occurrence(s)
🌐 186.189.204.xxx: 83 occurrence(s)
🌐 58.69.56.xxx: 66 occurrence(s)
🌐 186.10.24.xxx: 44 occurrence(s)
🌐 171.235.174.xxx: 44 occurrence(s)
🌐 113.160.206.xxx: 34 occurrence(s)
🌐 203.92.41.xxx: 33 occurrence(s)
🌐 94.245.132.xxx: 22 occurrence(s)
🌐 61.228.72.xxx: 22 occurrence(s)
🌐 202.88.244.xxx: 22 occurrence(s)
🌐 202.88.237.xxx: 22 occurrence(s)
🌐 187.146.87.xxx: 22 occurrence(s)
🌐 180.165.7.xxx: 22 occurrence(s)
🌐 123.27.129.xxx: 22 occurrence(s)
🌐 122.176.72.xxx: 22 occurrence(s)
🌐 117.236.227.xxx: 22 occurrence(s)
🌐 114.24.34.xxx: 22 occurrence(s)
🌐 203.160.71.xxx: 11 occurrence(s)
🌐 201.187.98.xxx: 11 occurrence(s)
🌐 192.140.149.xxx: 11 occurrence(s)
🌐 186.10.23.xxx: 11 occurrence(s)
🌐 125.20.128.xxx: 10 occurrence(s)
🌐 118.194.251.xxx: 4 occurrence(s)
🌐 35.216.211.xxx: 3 occurrence(s)
🌐 35.216.195.xxx: 3 occurrence(s)
🌐 89.132.90.xxx: 2 occurrence(s)
🌐 84.40.68.xxx: 2 occurrence(s)
🌐 37.46.233.xxx: 2 occurrence(s)
🌐 222.127.97.xxx: 2 occurrence(s)
🌐 217.23.131.xxx: 2 occurrence(s)
🌐 190.89.29.xxx: 2 occurrence(s)
🌐 177.47.193.xxx: 2 occurrence(s)
🌐 177.158.142.xxx: 2 occurrence(s)
🌐 176.97.58.xxx: 2 occurrence(s)
🌐 171.247.206.xxx: 2 occurrence(s)
🌐 154.66.156.xxx: 2 occurrence(s)
🌐 154.121.66.xxx: 2 occurrence(s)
🌐 152.52.85.xxx: 2 occurrence(s)
🌐 118.113.146.xxx: 2 occurrence(s)
🌐 117.192.235.xxx: 2 occurrence(s)
🌐 103.234.253.xxx: 2 occurrence(s)
🌐 103.14.72.xxx: 2 occurrence(s)
🌐 34.79.161.xxx: 1 occurrence(s)
🌐 34.34.146.xxx: 1 occurrence(s)
🌐 185.195.27.xxx: 1 occurrence(s)
🌐 104.155.11.xxx: 1 occurrence(s)

List of Computers:
🖥️ null: 12113 occurrence(s)
🖥️ abuse_xmco_fr: 6 occurrence(s)
🖥️ 35.227.142.181: 3 occurrence(s)
🖥️ windows: 2 occurrence(s)
🖥️ win-j9d866esij2: 1 occurrence(s)

[Armada/US-East] #opencanary Samba Access Summary for Mar 16

This OpenCanary received 5 file sample(s) yesterday.

File hashes seen:
► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 5 file(s)
https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71

List of Usernames:
👤 administrator: 255 occurrence(s)
👤 admin: 87 occurrence(s)
👤 guest: 12 occurrence(s)
👤 user: 3 occurrence(s)

List of IP Addresses:
🌐 218.205.64.xxx: 345 occurrence(s)
🌐 58.69.118.xxx: 44 occurrence(s)
🌐 45.238.143.xxx: 44 occurrence(s)
🌐 222.124.139.xxx: 44 occurrence(s)
🌐 14.182.224.xxx: 42 occurrence(s)
🌐 122.52.190.xxx: 22 occurrence(s)
🌐 1.163.162.xxx: 22 occurrence(s)
🌐 122.118.179.xxx: 11 occurrence(s)
🌐 117.240.78.xxx: 11 occurrence(s)
🌐 46.105.132.xxx: 5 occurrence(s)
🌐 34.140.108.xxx: 5 occurrence(s)
🌐 152.32.206.xxx: 4 occurrence(s)
🌐 102.33.152.xxx: 4 occurrence(s)
🌐 87.70.156.xxx: 3 occurrence(s)
🌐 45.156.129.xxx: 3 occurrence(s)
🌐 87.253.47.xxx: 2 occurrence(s)
🌐 86.122.194.xxx: 2 occurrence(s)
🌐 42.116.197.xxx: 2 occurrence(s)
🌐 41.40.247.xxx: 2 occurrence(s)
🌐 113.184.102.xxx: 2 occurrence(s)
🌐 109.75.64.xxx: 2 occurrence(s)
🌐 103.208.227.xxx: 2 occurrence(s)
🌐 101.51.25.xxx: 2 occurrence(s)
🌐 91.134.5.xxx: 1 occurrence(s)
🌐 34.78.249.xxx: 1 occurrence(s)
🌐 34.76.68.xxx: 1 occurrence(s)
🌐 34.140.170.xxx: 1 occurrence(s)
🌐 185.195.24.xxx: 1 occurrence(s)
🌐 180.242.100.xxx: 1 occurrence(s)
🌐 164.92.244.xxx: 1 occurrence(s)

List of Computers:
🖥️ null: 16 occurrence(s)
🖥️ windows: 7 occurrence(s)
🖥️ 9c9ddb975360: 5 occurrence(s)
🖥️ desktop-9iukqe5: 3 occurrence(s)
🖥️ 35.231.180.248: 3 occurrence(s)
🖥️ win-j9d866esij2: 1 occurrence(s)
🖥️ urlscan1fr: 1 occurrence(s)

[Digger/CH] #opencanary Samba Access Summary for Mar 16

This OpenCanary received 0 file sample(s) yesterday.

File hashes seen:

List of Usernames:
👤 administrator: 25 occurrence(s)
👤 guest: 11 occurrence(s)

List of IP Addresses:
🌐 152.32.200.xxx: 8 occurrence(s)
🌐 100.99.141.xxx: 3 occurrence(s)
🌐 95.104.113.xxx: 2 occurrence(s)
🌐 94.190.106.xxx: 2 occurrence(s)
🌐 41.33.105.xxx: 2 occurrence(s)
🌐 2.85.17.xxx: 2 occurrence(s)
🌐 200.75.2.xxx: 2 occurrence(s)
🌐 193.106.201.xxx: 2 occurrence(s)
🌐 188.69.167.xxx: 2 occurrence(s)
🌐 125.118.74.xxx: 2 occurrence(s)
🌐 111.65.33.xxx: 2 occurrence(s)
🌐 105.40.141.xxx: 2 occurrence(s)
🌐 103.218.229.xxx: 2 occurrence(s)
🌐 103.149.9.xxx: 2 occurrence(s)
🌐 34.79.232.xxx: 1 occurrence(s)
🌐 34.77.127.xxx: 1 occurrence(s)
🌐 34.52.173.xxx: 1 occurrence(s)
🌐 165.227.173.xxx: 1 occurrence(s)
🌐 109.69.58.xxx: 1 occurrence(s)

List of Computers:
🖥️ 188.63.199.224: 7 occurrence(s)
🖥️ mobile: 3 occurrence(s)
🖥️ win-j9d866esij2: 1 occurrence(s)
🖥️ windows: 1 occurrence(s)

[Sentinel/US-West] #opencanary analysis for yesterday

Summary:
🔄 Total Connection Attempts: 24929
👤 Unique Usernames: 110
🔑 Distinct Passwords: 1226
🌐 Unique Attacker IPs: 646

Port Popularity (Port / Count):
🖥️ VNC: 11994
🔐 SSH: 5208
🗄️ SMB: 3340
🖥️ RDP: 2301
🗃️ MSSQL: 1480
💻 Telnet: 270
📂 FTP: 171
🐬 MySQL: 113
🔴 REDIS: 52

Top 10 Usernames (Username / Count):
👤 root: 1191
👤 hello: 1019
👤 35: 311
👤 admin: 85
👤 administrator: 22
👤 user: 16
👤 www-data: 16
👤 user123: 15
👤 wwwroot: 14
👤 test: 14

Top 10 Passwords (Password / Count):
🔑 admin: 23
🔑 password: 21
🔑 12345: 17
🔑 123456: 13
🔑 1234: 13
🔑 system: 11
🔑 12345678: 10
🔑 root: 9
🔑 taZz@23495859: 9
🔑 pass: 7

Top 10 Attacker IPs (IP / Count):
🌐 146.235.215.xxx: 2593
🌐 36.85.253.xxx: 2297
🌐 127.0.0.xxx: 1436
🌐 45.227.254.xxx: 1286
🌐 193.24.123.xxx: 1148
🌐 103.89.233.xxx: 534
🌐 141.98.11.xxx: 484
🌐 202.88.241.xxx: 429
🌐 108.165.230.xxx: 405
🌐 37.148.132.xxx: 380

The OpenCanary Experience is at https://www.toce.ch

[Digger/CH] #opencanary analysis for yesterday

Summary:
🔄 Total Connection Attempts: 25474
👤 Unique Usernames: 870
🔑 Distinct Passwords: 1574
🌐 Unique Attacker IPs: 586

Port Popularity (Port / Count):
🔐 SSH: 12639
🖥️ RDP: 11748
💻 Telnet: 406
🖥️ VNC: 215
🗃️ MSSQL: 184
❓ 27017: 84
🐬 MySQL: 75
🔴 REDIS: 56
🗄️ SMB: 56
📡 Synology DSM: 9
📂 FTP: 2

Top 10 Usernames (Username / Count):
👤 test: 5489
👤 root: 1423
👤 admin: 380
👤 user: 256
👤 188: 224
👤 ubuntu: 172
👤 hello: 163
👤 debian: 112
👤 deploy: 39
👤 guest: 32

Top 10 Passwords (Password / Count):
🔑 123456: 271
🔑 1234: 141
🔑 123: 124
🔑 password: 120
🔑 12345678: 119
🔑 12345: 112
🔑 admin: 72
🔑 qwerty: 37
🔑 123456789: 37
🔑 root: 35

Top 10 Attacker IPs (IP / Count):
🌐 185.156.73.xxx: 11029
🌐 113.0.152.xxx: 1326
🌐 209.38.27.xxx: 644
🌐 204.48.21.xxx: 636
🌐 113.240.110.xxx: 525
🌐 43.228.104.xxx: 478
🌐 209.38.25.xxx: 444
🌐 209.245.235.xxx: 321
🌐 121.78.39.xxx: 307
🌐 165.245.177.xxx: 301

The OpenCanary Experience is at https://www.toce.ch

[Armada/US-East] #opencanary Samba Access Summary for Mar 15

This OpenCanary received 18 file sample(s) yesterday.

File hashes seen:
► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 18 file(s)
https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71

List of Usernames:
👤 administrator: 8144 occurrence(s)
👤 admin: 4217 occurrence(s)
👤 hp: 3887 occurrence(s)
👤 machine: 53 occurrence(s)
👤 hmspares: 49 occurrence(s)
👤 guest: 1 occurrence(s)
👤 message: occurrence(s)
👤 message: occurrence(s)
👤 message: occurrence(s)
👤 message: occurrence(s)

List of IP Addresses:
🌐 202.58.95.xxx: 12949 occurrence(s)
🌐 36.85.253.xxx: 2300 occurrence(s)
🌐 115.242.147.xxx: 682 occurrence(s)
🌐 103.89.233.xxx: 538 occurrence(s)
🌐 115.243.236.xxx: 308 occurrence(s)
🌐 219.130.137.xxx: 263 occurrence(s)
🌐 186.189.204.xxx: 259 occurrence(s)
🌐 196.188.104.xxx: 193 occurrence(s)
🌐 117.5.161.xxx: 110 occurrence(s)
🌐 49.151.213.xxx: 44 occurrence(s)
🌐 186.10.74.xxx: 44 occurrence(s)
🌐 114.24.34.xxx: 44 occurrence(s)
🌐 89.252.106.xxx: 22 occurrence(s)
🌐 59.88.7.xxx: 22 occurrence(s)
🌐 41.33.240.xxx: 22 occurrence(s)
🌐 41.229.234.xxx: 22 occurrence(s)
🌐 37.52.12.xxx: 22 occurrence(s)
🌐 202.88.244.xxx: 22 occurrence(s)
🌐 186.67.186.xxx: 22 occurrence(s)
🌐 186.67.106.xxx: 22 occurrence(s)
🌐 152.230.27.xxx: 22 occurrence(s)
🌐 136.226.250.xxx: 22 occurrence(s)
🌐 111.240.102.xxx: 22 occurrence(s)
🌐 106.219.251.xxx: 22 occurrence(s)
🌐 103.16.71.xxx: 22 occurrence(s)
🌐 103.109.176.xxx: 22 occurrence(s)
🌐 122.52.231.xxx: 12 occurrence(s)
🌐 59.115.187.xxx: 11 occurrence(s)
🌐 202.164.139.xxx: 11 occurrence(s)
🌐 192.140.149.xxx: 11 occurrence(s)
🌐 150.129.182.xxx: 11 occurrence(s)
🌐 120.89.64.xxx: 11 occurrence(s)
🌐 118.163.224.xxx: 11 occurrence(s)
🌐 71.6.135.xxx: 3 occurrence(s)
🌐 94.59.158.xxx: 2 occurrence(s)
🌐 93.170.45.xxx: 2 occurrence(s)
🌐 83.145.162.xxx: 2 occurrence(s)
🌐 81.10.26.xxx: 2 occurrence(s)
🌐 77.87.102.xxx: 2 occurrence(s)
🌐 72.255.39.xxx: 2 occurrence(s)
🌐 58.181.27.xxx: 2 occurrence(s)
🌐 45.9.44.xxx: 2 occurrence(s)
🌐 41.210.145.xxx: 2 occurrence(s)
🌐 36.72.135.xxx: 2 occurrence(s)
🌐 222.127.97.xxx: 2 occurrence(s)
🌐 181.191.210.xxx: 2 occurrence(s)
🌐 180.251.226.xxx: 2 occurrence(s)
🌐 14.191.172.xxx: 2 occurrence(s)
🌐 136.232.196.xxx: 2 occurrence(s)
🌐 113.160.151.xxx: 2 occurrence(s)
🌐 45.151.181.xxx: 1 occurrence(s)
🌐 34.78.50.xxx: 1 occurrence(s)
🌐 178.128.207.xxx: 1 occurrence(s)
🌐 142.93.143.xxx: 1 occurrence(s)

List of Computers:
🖥️ null: 12009 occurrence(s)
🖥️ shodan: 3 occurrence(s)

[Armada/US-East] #opencanary Samba Access Summary for Mar 15

This OpenCanary received 0 file sample(s) yesterday.

File hashes seen:

List of Usernames:
👤 administrator: 30 occurrence(s)
👤 guest: 6 occurrence(s)

List of IP Addresses:
🌐 222.124.139.xxx: 66 occurrence(s)
🌐 58.69.118.xxx: 44 occurrence(s)
🌐 49.229.50.xxx: 22 occurrence(s)
🌐 1.174.213.xxx: 22 occurrence(s)
🌐 114.47.91.xxx: 11 occurrence(s)
🌐 1.163.162.xxx: 11 occurrence(s)
🌐 34.79.162.xxx: 5 occurrence(s)
🌐 35.216.211.xxx: 3 occurrence(s)
🌐 35.216.168.xxx: 3 occurrence(s)
🌐 34.79.181.xxx: 3 occurrence(s)
🌐 95.25.56.xxx: 2 occurrence(s)
🌐 88.249.34.xxx: 2 occurrence(s)
🌐 41.33.134.xxx: 2 occurrence(s)
🌐 39.184.170.xxx: 2 occurrence(s)
🌐 36.91.98.xxx: 2 occurrence(s)
🌐 200.44.194.xxx: 2 occurrence(s)
🌐 2.192.81.xxx: 2 occurrence(s)
🌐 196.202.42.xxx: 2 occurrence(s)
🌐 187.188.23.xxx: 2 occurrence(s)
🌐 14.250.89.xxx: 2 occurrence(s)
🌐 123.22.142.xxx: 2 occurrence(s)
🌐 118.70.49.xxx: 2 occurrence(s)
🌐 113.21.38.xxx: 2 occurrence(s)
🌐 113.170.55.xxx: 2 occurrence(s)
🌐 109.110.52.xxx: 2 occurrence(s)
🌐 46.101.1.xxx: 1 occurrence(s)
🌐 34.77.151.xxx: 1 occurrence(s)
🌐 34.38.220.xxx: 1 occurrence(s)
🌐 34.34.173.xxx: 1 occurrence(s)
🌐 34.14.46.xxx: 1 occurrence(s)
🌐 146.148.113.xxx: 1 occurrence(s)

List of Computers:
🖥️ windows: 9 occurrence(s)
🖥️ abuse_xmco_fr: 6 occurrence(s)

[Digger/CH] #opencanary Samba Access Summary for Mar 15

This OpenCanary received 4 file sample(s) yesterday.

File hashes seen:
► 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71 : 4 file(s)
https://www.virustotal.com/gui/file/3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71

List of Usernames:
👤 guest: 23 occurrence(s)
👤 administrator: 8 occurrence(s)
👤 message: occurrence(s)

List of IP Addresses:
🌐 41.10.117.xxx: 22 occurrence(s)
🌐 189.180.103.xxx: 22 occurrence(s)
🌐 122.173.26.xxx: 22 occurrence(s)
🌐 197.254.238.xxx: 21 occurrence(s)
🌐 46.105.132.xxx: 13 occurrence(s)
🌐 35.216.211.xxx: 5 occurrence(s)
🌐 35.216.168.xxx: 5 occurrence(s)
🌐 71.6.199.xxx: 3 occurrence(s)
🌐 188.65.244.xxx: 2 occurrence(s)
🌐 186.229.28.xxx: 2 occurrence(s)
🌐 183.249.114.xxx: 2 occurrence(s)
🌐 183.182.99.xxx: 2 occurrence(s)
🌐 49.51.228.xxx: 1 occurrence(s)
🌐 34.77.191.xxx: 1 occurrence(s)
🌐 34.77.181.xxx: 1 occurrence(s)
🌐 146.148.113.xxx: 1 occurrence(s)
🌐 104.155.43.xxx: 1 occurrence(s)

List of Computers:
🖥️ abuse_xmco_fr: 10 occurrence(s)
🖥️ 9c9ddb975360: 7 occurrence(s)
🖥️ 06bf6c5935aa: 6 occurrence(s)
🖥️ windows: 3 occurrence(s)
🖥️ shodan: 3 occurrence(s)