{"id":93316,"date":"2020-09-05T19:42:19","date_gmt":"2020-09-05T17:42:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/analiz-aktivnosti-atakuyushhih-svyazannoj-s-podborom-parolej-po-ssh"},"modified":"2020-09-05T19:42:19","modified_gmt":"2020-09-05T17:42:19","slug":"analiz-aktivnosti-atakuyushhih-svyazannoj-s-podborom-parolej-po-ssh","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/analiz-aktivnosti-atakuyushhih-svyazannoj-s-podborom-parolej-po-ssh","title":{"rendered":"Analysis of attacker activity related to SSH password cracking","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/systemoverlord.com\/2020\/09\/04\/lessons-learned-from-ssh-credential-honeypots.html\">Published<\/a><\/noindex> results of the analysis of attacks related to password guessing on SSH servers. During the experiment, several honeypots were launched, impersonating an accessible OpenSSH server and deployed across various cloud provider networks such as<br \/>\nGoogle Cloud, DigitalOcean, and NameCheap. Over three months, a total of 929,554 connection attempts to the server were recorded.<\/p>\n<p>In 78% of cases, the attempts were aimed at determining the root user password. The most commonly checked passwords were '123456' and 'password', but among the top ten was also the password 'J5cmmu=Kyf0-br8CsW', likely used as a default by some manufacturer.<\/p>\n<p>Most popular usernames and passwords:<\/p>\n<p><center><\/p>\n<p>      Login<br \/>\n      Number of attempts<br \/>\n      Password<br \/>\n      Number of attempts<\/p>\n<p>      root<br \/>\n      729108<\/p>\n<p>      40556<\/p>\n<p>      admin<br \/>\n      23302<br \/>\n      123456<br \/>\n      14542<\/p>\n<p>      user<br \/>\n      8420<br \/>\n      admin<br \/>\n      7757<\/p>\n<p>      test<br \/>\n      7547<br \/>\n      123<br \/>\n      7355<\/p>\n<p>      oracle<br \/>\n      6211<br \/>\n      1234<br \/>\n      7099<\/p>\n<p>      ftpuser<br \/>\n      4012<br \/>\n      root<br \/>\n      6999<\/p>\n<p>      ubuntu<br \/>\n      3657<br \/>\n      password<br \/>\n      6118<\/p>\n<p>      guest<br \/>\n      3606<br \/>\n      test<br \/>\n      5671<\/p>\n<p>      postgres<br \/>\n      3455<br \/>\n      12345<br \/>\n      5223<\/p>\n<p>      usuario<br \/>\n      2876<br \/>\n      guest<br \/>\n      4423<\/p>\n<p><\/center><\/p>\n<p>From the analyzed guessing attempts, 128,588 unique login-password pairs were identified, with 38,112 of them being tested 5 or more times. The 25 most frequently checked pairs:<\/p>\n<p><center><\/p>\n<p>      Login<br \/>\n      Password<br \/>\n      Number of attempts<\/p>\n<p>      root<br \/>\n      \u00a0<br \/>\n      37580<\/p>\n<p>      root<br \/>\n      root<br \/>\n      4213<\/p>\n<p>      user<br \/>\n      user<br \/>\n      2794<\/p>\n<p>      root<br \/>\n      123456<br \/>\n      2569<\/p>\n<p>      test<br \/>\n      test<br \/>\n      2532<\/p>\n<p>      admin<br \/>\n      admin<br \/>\n      2531<\/p>\n<p>      root<br \/>\n      admin<br \/>\n      2185<\/p>\n<p>      guest<br \/>\n      guest<br \/>\n      2143<\/p>\n<p>      root<br \/>\n      password<br \/>\n      2128<\/p>\n<p>      oracle<br \/>\n      oracle<br \/>\n      1869<\/p>\n<p>      ubuntu<br \/>\n      ubuntu<br \/>\n      1811<\/p>\n<p>      root<br \/>\n      1234<br \/>\n      1681<\/p>\n<p>      root<br \/>\n      123<br \/>\n      1658<\/p>\n<p>      postgres<br \/>\n      postgres<br \/>\n      1594<\/p>\n<p>      support<br \/>\n      support<br \/>\n      1535<\/p>\n<p>      jenkins<br \/>\n      jenkins<br \/>\n      1360<\/p>\n<p>      admin<br \/>\n      password<br \/>\n      1241<\/p>\n<p>      root<br \/>\n      12345<br \/>\n      1177<\/p>\n<p>      raspberry<br \/>\n      raspberry<br \/>\n      1160<\/p>\n<p>      root<br \/>\n      12345678<br \/>\n      1126<\/p>\n<p>      root<br \/>\n      123456789<br \/>\n      1069<\/p>\n<p>      ubnt<br \/>\n      ubnt<br \/>\n      1069<\/p>\n<p>      admin<br \/>\n      1234<br \/>\n      1012<\/p>\n<p>      root<br \/>\n      1234567890<br \/>\n      967<\/p>\n<p>      ec2-user<br \/>\n      ec2-user<br \/>\n      963<\/p>\n<p><\/center><\/p>\n<p>Distribution of scanning attempts by days of the week and hours:<br \/>\n<center><noindex><a rel=\"nofollow\" href=\"https:\/\/systemoverlord.com\/img\/gopot\/days_of_week.png\"><img decoding=\"async\" alt=\"Analysis of attacker activity related to SSH password cracking\" src=\"\/wp-content\/uploads\/2020\/09\/2e567be6dd9381ab5ea3bf25597e6ebb.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/systemoverlord.com\/img\/gopot\/hours.png\"><img decoding=\"async\" alt=\"Analysis of attacker activity related to SSH password cracking\" src=\"\/wp-content\/uploads\/2020\/09\/108d5657630048e4e5e026e188f682ec.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>A total of 27,448 unique requests were recorded <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/lir\/ipv4\/\"   title=\"(the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community.\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"822\">(the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community.<\/a>.<br \/>\nThe highest number of checks performed from a single IP was 64,969. The share of checks through Tor was only 0.8%. 62.2% of the IP addresses involved in the attempts were associated with Chinese subnets:<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/pics_base\/0_1599283349.png\"><img decoding=\"async\" alt=\"Analysis of attacker activity related to SSH password cracking\" src=\"\/wp-content\/uploads\/2020\/09\/e8b45b6d74e06347b02a4643464b019d.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53663\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0430\u0442\u0430\u043a, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0445 \u0441 \u043f\u043e\u0434\u0431\u043e\u0440\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c \u043f\u043e SSH. \u0412 \u0445\u043e\u0434\u0435 \u044d\u043a\u0441\u043f\u0435\u0440\u0438\u043c\u0435\u043d\u0442\u0430 \u0431\u044b\u043b\u043e \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043b\u043e\u0432\u0443\u0448\u0435\u043a (honeypot), \u043f\u0440\u0438\u0442\u0432\u043e\u0440\u044f\u044e\u0449\u0438\u0445\u0441\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c OpenSSH \u0438 \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u0432 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0441\u0435\u0442\u044f\u0445 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432, \u0442\u0430\u043a\u0438\u0445 \u043a\u0430\u043a Google Cloud, DigitalOcean \u0438 NameCheap. \u0417\u0430 \u0442\u0440\u0438 \u043c\u0435\u0441\u044f\u0446\u0430 \u0431\u044b\u043b\u043e \u0437\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043e 929554 \u043f\u043e\u043f\u044b\u0442\u043a\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0443. \u0412 78% \u0441\u043b\u0443\u0447\u0430\u044f\u0445 \u043f\u043e\u0434\u0431\u043e\u0440 \u0431\u044b\u043b \u043d\u0430\u0446\u0435\u043b\u0435\u043d \u043d\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":93317,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-93316","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0430\u0442\u0430\u043a, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0445 \u0441 \u043f\u043e\u0434\u0431\u043e\u0440\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/analiz-aktivnosti-atakuyushhih-svyazannoj-s-podborom-parolej-po-ssh\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u043d\u0430\u043b\u0438\u0437 \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0445, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u043e\u0439 \u0441 \u043f\u043e\u0434\u0431\u043e\u0440\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043f\u043e SSH | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0430\u0442\u0430\u043a, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0445 \u0441 \u043f\u043e\u0434\u0431\u043e\u0440\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/analiz-aktivnosti-atakuyushhih-svyazannoj-s-podborom-parolej-po-ssh\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-05T17:42:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-05T17:42:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Analysis of attacker activity related to SSH password guessing | ProHoster","description":"The results of the analysis of password guessing attacks on servers have been published.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/analiz-aktivnosti-atakuyushhih-svyazannoj-s-podborom-parolej-po-ssh","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u043d\u0430\u043b\u0438\u0437 \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0445, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u043e\u0439 \u0441 \u043f\u043e\u0434\u0431\u043e\u0440\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043f\u043e SSH | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0430\u0442\u0430\u043a, \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0445 \u0441 \u043f\u043e\u0434\u0431\u043e\u0440\u043e\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043a \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/analiz-aktivnosti-atakuyushhih-svyazannoj-s-podborom-parolej-po-ssh","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-05T17:42:19+00:00","article:modified_time":"2020-09-05T17:42:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"93316","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:50:29","updated":"2026-02-08 20:40:13","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/93316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=93316"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/93316\/revisions"}],"predecessor-version":[{"id":158013,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/93316\/revisions\/158013"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/93317"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=93316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=93316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=93316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}