What attackers are trying right now
Real, unsolicited login attempts against monitored infrastructure, captured as they happened. Someone scanned, picked a device, and tried to authenticate. This is what they were after — and exactly what they typed.
Loading live capture data…
The last 30 days at a glance
The same capture, summarised: which devices drew the most interest, which credentials were tried most often, and where the traffic came from.
Over the last 30 days, PacketViper recorded 43,756 unsolicited login and reconnaissance attempts from 13,458 unique source IP addresses in 145 countries, against 60 distinct device types. 507 different username and password combinations were tried. Last updated 2026-08-16 19:18 UTC.
The most frequently targeted devices were Cisco Catalyst 2960-X, Microsoft Active Directory (WS2022), Linux Telnetd 1 0, Mikrotik Routeros 7 14 and VMware ESXi 7.0.
Most targeted devices
| Device | Attempts | Unique sources |
|---|---|---|
| Cisco Catalyst 2960-X | 14,838 | 4,308 |
| Microsoft Active Directory (WS2022) | 4,399 | 596 |
| Linux Telnetd 1 0 | 2,341 | 1,214 |
| Mikrotik Routeros 7 14 | 2,156 | 1,112 |
| VMware ESXi 7.0 | 1,728 | 218 |
| Dell iDRAC9 | 1,712 | 569 |
| Microsoft Exchange Server 2019 | 1,605 | 571 |
| Cisco ASA 5516-X | 1,406 | 667 |
| Juniper MX480 | 1,318 | 688 |
| Aruba Networks Arubaos 2930F | 1,246 | 655 |
| Check Point R81 Gateway | 1,227 | 712 |
| Apache Log4j | 1,000 | 572 |
Most-attempted credentials
| Username | Password | Attempts |
|---|---|---|
| admin | admin | 132 |
| root | Zte521 | 56 |
| root | (none) | 42 |
| root | xc3511 | 38 |
| root | root | 37 |
| user | user | 29 |
| admin | 1234 | 26 |
| ftp | ftp | 25 |
| default | default | 25 |
| *1 | $4 | 24 |
| ;�admin.$cmd����hello�?>�admin.$cmd����isMaster�… | (none) | 23 |
| root | vizxv | 23 |
| admin | admin1234 | 21 |
| root | hi3518 | 21 |
| ubnt | ubnt | 20 |
Where the attempts came from
| Country | Attempts | Unique sources |
|---|---|---|
| United States | 15,590 | 3,807 |
| Britain (UK) | 2,936 | 1,331 |
| Pakistan | 2,907 | 462 |
| Ukraine | 2,608 | 1,025 |
| China | 2,416 | 1,082 |
| Iran | 2,351 | 52 |
| Russia | 2,105 | 498 |
| Argentina | 1,358 | 687 |
| Brazil | 1,273 | 632 |
| Netherlands | 867 | 168 |
| France | 637 | 356 |
| Canada | 594 | 59 |
Networks the attempts originated from
| Operator | ASN | Attempts |
|---|---|---|
| GOOGLE-CLOUD-PLATFORM | AS396982 | 3,845 |
| MICROSOFT-CORP-MSN-AS-BLOCK | AS8075 | 2,622 |
| Iran Telecommunication Company PJS | AS58224 | 2,158 |
| Akamai Connected Cloud | AS63949 | 1,598 |
| Censys, Inc. | AS398324 | 1,461 |
| Cyber Internet Services Pvt Ltd. | AS9541 | 1,154 |
| DIGITALOCEAN-ASN | AS14061 | 1,064 |
| AMAZON-02 | AS16509 | 995 |
| Hydra Communications Ltd | AS25369 | 896 |
| Rostelecom | AS12683 | 829 |
| Chinanet | AS4134 | 811 |
| CHINA UNICOM China169 Backbone | AS4837 | 793 |
How this data is captured
Preemptive defense turns an attacker’s first move into intelligence — before anything of value is touched.
Moving, not static
Static defenses get mapped, and a map is all an attacker needs. Automated Moving Target Defense keeps changing what can be seen and reached, so the picture an attacker assembles is stale before they can act on it. Effort gets spent on ground that has already shifted.
The attempt is the signal
A blocked connection is not a solved problem — it is the beginning of an investigation. Each attempt here carries context: which device drew interest, from where, on which service, and with which credentials. That is what a block count can never tell you.
Credentials, captured intact
The usernames and passwords shown are recorded exactly as submitted. They are the live contents of real attack dictionaries — and a direct answer to the question every operator should ask: would these have worked on my network?
How to read this page
Method
Window: a rolling 30 days of captured activity.
Refresh: the page rebuilds hourly from the live capture store.
Attack Target: the device the source was attempting to authenticate against.
Attempts From Source: that source’s full total for the window, not just the rows shown.
Limits worth stating
Country is derived from the regional internet registry allocation for the source network. That is a registration fact, not a physical location — traffic routed through hosting providers or VPNs will show the registered country of the network, not the operator.
A source address is not a culprit. Many are compromised third-party hosts being used by someone else.
Volume is capped for readability at the 25 most recent attempts per source, so one high-volume scanner cannot fill the table.
Common questions
What usernames and passwords do attackers try most often?
Across the last 30 days the most-attempted combinations were: admin / admin (132 attempts); root / Zte521 (56 attempts); root / no password (42 attempts); root / xc3511 (38 attempts); root / root (37 attempts). These are the live contents of real attack dictionaries, recorded exactly as submitted.
Which devices do attackers target most?
The most frequently targeted devices were Cisco Catalyst 2960-X, Microsoft Active Directory (WS2022), Linux Telnetd 1 0, Mikrotik Routeros 7 14 and VMware ESXi 7.0. In total 60 distinct device types drew unsolicited authentication or reconnaissance attempts.
Which countries do these attacks come from?
By volume the largest sources were United States, Britain (UK), Pakistan, Ukraine and China. Country is derived from the regional internet registry allocation for the source network, which is a registration fact rather than a physical location: traffic routed through hosting providers or VPNs shows the registered country of that network, not the operator behind it.
Is this real attack data?
Yes. Every row is an unsolicited attempt against monitored infrastructure, recorded as it happened. Nothing is simulated or synthesised. The page refreshes hourly and shows a rolling 30-day window.
Does a source IP address identify the attacker?
No. Many source addresses are compromised third-party hosts, or shared hosting and VPN exit points being used by someone else. A source address indicates where traffic arrived from, not who is responsible for it.
See It On Your Network
This is one network’s view. Now picture your plant floor.
PacketViper runs inline in OT and IT networks — agentless, non-intrusive, and surgical enough to scope enforcement to a single device instead of an entire subnet.