Abstract digital connections background

The OpenCanary Experience · Genesis

The internet is a dirty, dirty place. In 2023, I rebuilt the proof.

A rough first attempt in 2022 hinted at the scale. On 11 October 2023 a successor went live — more sensors, more protocols, and built to catch what the first one never could.

Scroll, swipe, or use the arrow keys.

Before · 2022

197 days in the wilderness.

The first generation was one Oracle Cloud VM with four ports open — FTP, SSH, Telnet, a fake web login. I left it to fester. It could only count knocks; it never saw a single password. And still:

Days alive
197
one VM, four ports
Total knocks
0
the internet found it anyway
SSH · 22
0
hunting for a shell
Telnet · 23
0
hunting for a shell

SSH and Telnet were 99% of it — relentless attempts to reach a command prompt. Hammered hardest from 61.177.17x.x, China. A humble ancestor, but proof the question was worth asking properly.

The successor goes live

Genesis Day: October 11th 2023.

Six sensors this time — scrappy and half-named (oc-at-home, US-West and US-WEST) — across eleven protocols, built not just to count knocks but to capture: credentials, and files. The first knock came in 10 seconds.

10seconds to the first connection attempt
11 Oct · ignition
0
12 Oct
0
13 Oct
0

Nothing, nothing, nothing — then the internet noticed. From a standing start to 164,511 connections a day inside 72 hours.

The evolution

What 197 days became in 82.

 Gen-1 · 2022Genesis · 2023
Total volume328,347 / 197 days10,262,671 / 82 days
Per day1,667125,154  (~75×)
Per hour~420~5,200
Attack surface4 ports11 protocols
What it could seeconnection countscredentials + malware

Roughly seventy-five times the daily volume — and for the first time, the ability to see what was being tried, not just how often.

Genesis · protocol detail

Eleven protocols, and a clock that never sleeps.

SSH · 223,080,161
RDP · 33892,991,480
VNC · 59012,107,601
MSSQL · 14331,318,223
Telnet · 23436,222
Redis · 6379204,591
MySQL · 330693,908
FTP · 2126,905
HTTP · 803,525
GIT · 941855

From 2 targets to 11

Gen-1 saw only SSH and Telnet. Genesis saw the full menu — RDP, VNC, MSSQL, Redis — but remote-access still dominated: SSH, RDP, VNC and Telnet were 84% of everything.

No human curve

Hourly volume never dropped below 349,214 and topped out at 479,990. A flat line around the clock — the signature of automation, not people. The machines do not sleep.

The tyranny of the default

Gen-1 could only count. Genesis captured the keys.

In 2022 I could name the Known Dumb Credentials — 1234, admin, default, 888888 — but never count them. Now I could. Same keys, finally measured:

🦠 The same old keys, now quantified

UsernamePasswordAttempts
adminadmin13,225
rootroot10,587
rootadmin10,411
supportsupport8,640
rootvizxv8,319
rootxc35116,680

vizxv and xc3511 are verbatim Mirai defaults — IoT cameras and routers, not people. Default credentials on an internet-facing host are compromised in minutes. Gen-1 suspected it; Genesis proved it.

What really happened

I set a trap for a thief. The internet sent deposits.

I opened an SMB file share and planted a canary token, expecting someone to steal it and trip the alarm. Instead, they arrived to drop things.

Dropper IPs
0
worldwide, uncoordinated
Files written
0
random 8-char .exe names
Distinct binaries
1
all 53 byte-identical
Window
15–31 Dec
a concentrated campaign
116.211.95.182 (SMB3_00, "OSX")  create_file overwrite_if  ok  mvIbimPS.exe
103.139.156.210 (SMB3_00, "OSX")  create_file overwrite_if  ok  PRVCZyGM.exe
The binary they all dropped · SHA-1
23873bf2670cf64c2440058130548d4e4da412dd
VirusTotal: HackTool.RemoteExec / RemCom — a PsExec-style remote-execution tool.

Twenty unrelated IPs, the same spoofed SMB3_00 / OSX fingerprint, the same single binary written 53 times under random names. The token was never taken. The trap caught something better: a botnet using any open share it finds as a dead-drop to pre-stage its break-in tool. Sadly for the criminals, my "antivirus" solution moved their file. Immediately.

Who came knocking

Same dirty internet, now mapped.

Geography

Gen-1 saw China and little else. Genesis drew the whole map: China 2,092,059 · Lithuania 1,526,991 · Russia 1,331,749 · Netherlands 1,127,467. Tiny Lithuania at number two is one busy hosting range, not a nation.

Sources

One IP — 185.73.125.23 — fired 377,856 VNC probes alone. The Lithuanian 141.98.11.x block fills eight of the top twenty: a coordinated RDP farm.

The VNC paradox

2,107,601 VNC connections. Passwords that matched a known list: 4,610. Millions of attempts, near-total failure — brute force against a wall, running anyway.

Continuity

The 2022 floods from 61.177.17x.x never stopped — they were just a sliver of what Genesis could finally see in full. Same actors. Same tooling. Bigger lens.

Conclusion network visual

Genesis

Do it, or be a victim.

Open a port, and the internet answers in 10 seconds.

Default credentials are compromised in minutes. Proven.

Leave a share open, and they'll store their break-in kit on it.

0

The 2022 verdict, proven at ten-million scale — and now we can see the staging, not just the knocking. This was Genesis.

By 2026, the flock had grown — and so had what it saw.

The OpenCanary Experience →