
Based on the users that you have you could try to make a list of the usernames and use cme to see if they used their username as passwords.


Use cewl on their website just in case as well.

cewl http://fuse.fabricorp.local/papercut/logs/html/index.htm --with-numbers > wordlist
crackmapexec smb -u userlist.txt -p passlist

Spray SMB just in case.

hydra -L userlist.txt -P passlist.txt smb

