Last time I saw this an obscure single letter root password was still "secure", now days seems like almost all non-alphanumeric chars works. % is my new root password it still has not been brute forced.
No "credentials" are being "harvested" here. It's all worthless data, save for the statistics.
Having a root password of "toor" is very clever. Nobody will figure that one out.
Do most installations create a git user account with login permissions?
I'd be more curious to know what these SSH scanner bots actually do if they manage to log in. Automated recon, install spambot/cryptominer/phishing site, something else?