There's been tons of dumps posted. Normally I see the download or magnet links on Reddit or HN. Even with hashes people have broken 69% [0] to 85% [1] of the accounts. There's mailing list or forums for various related tools (cracking tools, gpu cracking, have I been pwned, etc.) that discuss these kinds of things, including where to get the passwords and/or hashes.
One of the summaries claimed that 3% of the cracked passwords were 12 characters long (some 1.9M). 48% of the cracked passwords were lower case and numbers.
Often a thread that mentions the compromise/leak also mentions the newest "batch" that includes the new entries. The last one I tracked was RockYou2021.txt, some 100GB, around 10GB compressed. Just use your favorite egrep/perl/python to filter for whatever you want. I checked the a random torrent and found 25 people on it.
I agree on your comments on the distribution, but the average user has shockingly little entropy, and human password entropy doesn't scale with password length. I expect a decent chunk of the passwords are going to be whatever the user's default password was and either repeating or extending it in obvious ways. Even the simplest approach of testing 2 words or 3 words for a total 12-15 characters with the simple 3/E i/one and 7/L replacements would likely. Granted I'm not expecting the same 8 character 69-85% with 12 characters, but I also don't expect much significantly less, and I believe 33M accounts were stolen.
[0] https://blog.korelogic.com/blog/2016/05/19/linkedin_password...
[1] https://www.trustedsec.com/blog/introduction-gpu-password-cr...