Abstract digital connections background

The OpenCanary Experience · 2026 Q1 · Database Season

Three years they hunted shells. This quarter, they came for the database.

Eighteen million knocks in ninety days — and two out of every three were aimed at a single port. Q1 2026 is the quarter the internet stopped looking for a login and started looking for your data.

Scroll, swipe, or use the arrow keys.

Q1 2026 · Jan – Mar · 90 days

The quarter at a glance.

Total connections
0
three sensors, eleven protocols
MSSQL share
66.5%
of everything — port 1433
Peak day
0
9 January 2026
New source IPs
0
fresh hosts in 90 days
Avg per day
199,478
connections, around the clock
Busiest hour
823,943
19:00 — barely above the 09:00 low of 657K
From Turkey
26.3%
a brand-new number one
Annualised pace
~72M
steady on 2025's 80M
Switzerland6,816,775
US-East5,831,062
US-West5,574,581

Balanced again — no single sensor dominated this quarter. The same internet found all three within a hair of each other.

The takeover · protocol detail

One port ate the chart.

MSSQL · 143311,944,212
SSH · 222,359,376
RDP · 33892,266,437
VNC · 59011,128,080
Telnet · 23180,992
Redis · 637949,486
MySQL · 330611,788
FTP · 2111,053
HTTP · 801,433
GIT · 941876
MSSQL vs SSH
5.06×
the next-biggest protocol
Blank-client probes
8,776,468
73.5% of MSSQL — bare TDS scans, no real login
ODBC clients
2,434,122
the largest named client
vs all of 2025
46%
one quarter = nearly half 2025's full-year MSSQL

Who drove it

The top four sources were all hunting databases.

This wasn't a broad crowd — a handful of relentless scanners carried the MSSQL flood. Every one of the four busiest IPs of the quarter was pointed at port 1433.

Source IPProtocolConnections
92.86.69.77MSSQL976,123
54.39.215.2MSSQL374,443
119.8.10.250MSSQL355,870
104.192.6.74MSSQL298,092
185.156.73.19RDP155,179
Worst single IP
976,123
92.86.69.77 — 5.4% of everything, one host
Top 4 IPs combined
2,004,528
all MSSQL — 17% of the whole port-1433 flood
104.192.6.74
298,092
the repeat MSSQL prober, three years running
First RDP source
#5
remote access didn't crack the top four

Who came knocking · and with what keys

A new flag at the top.

Turkey arrives at #1

A first for the archive: Turkey led with 4,729,465 — over a quarter of all traffic — ahead of United States 2,259,864, India 1,364,249, Romania 1,090,257 and Netherlands 961,753.

The old guard slips

China fell to 641,373 — sixth — and the usual European blocks thinned. Where last year's flood came from the Far East and the Baltics, this quarter it came from Anatolia.

Credentials — same defaults

admin/admin 6,964 · root/root 5,391 · root/admin 4,913. The most-tried password was still 123456 — 59,442 times.

The "hello" username

Behind the null RDP logins (1.09M), the second-commonest username was hello — submitted 520,689 times — then root (338,023) and test (141,716).

Meanwhile, on the file share

The usual suspect, year four.

While the internet hammered port 1433, the open SMB shares kept filling — with the same binary they've been dropping since 2023.

SMB events
0
across the three sensors
Malware files dropped
0
in 90 days
RemCom share
99.95%
of real malware — same hash as Genesis 2023
Everything else
1
file — a known repack variant
23873bf2…412dd  ×2,074  RemCom · HackTool.RemoteExec — the Genesis 2023 binary
8d451938…fb590  ×1  repack of 3c2fe308… — same size, new signature
+ 30 empty 0-byte files, discarded

Four years, three sensors, one tool. The protocols change, the geography changes — the payload never does.

Conclusion network visual

Q1 2026

The internet narrowed its aim to port 1433.

Two of every three knocks went at a database.

A handful of scanners carried the whole flood.

And the same file kept landing on the share.

0

Eighteen million knocks in ninety days, and the target has never been clearer. This was Database Season.

Next: Q2 2026.

The OpenCanary Experience →