You're on a right track. But there's a ton of variance, for example poorly built systems (used even today) store passwords in plaintext, so then it doesn't matter how complex your password is, it can still be used as a 'seed' to crack better protected databases. And properly salted+hashed database doesn't have any indication which password is poor and which is strong, so (at least I assume so) attackers just keep their algorithms running for however many hours they think is needed/worth the time and just stop processing once they have sufficient payout of the attack.
For example, without salting and using md5 hash 'password' gives hash '286755fad04869ca523320acce0dc6a4'. Using randomly generated 55 character password gives hash 'd1006257a2b09c76bcba82f209650056'. So, just a database with hashed passwords alone doesn't give you any information if the password is strong or weak.