Intelligence Report · Q2 2026

MSSQL:
Under Siege.

Three sensors. 14.6 million connection attempts across April, May and June. And nearly half of them aimed at one port — 1433. Q2 2026 was the quarter the databases took the hits.

Total connections
14.6M
3 sensors · 91 days (Apr–Jun)
MSSQL share
44%
6.30M hits on port 1433 · #1 protocol
Peak single day
513K
24 May 2026
New IPs per day
1,720
~157K fresh hosts over the quarter

Scroll or use arrow keys to navigate.

Protocol Breakdown

One port took nearly half.

Remote desktop usually leads. Not this quarter. MSSQL alone pulled 6.30 million hits — more than RDP, VNC and SSH did individually, and close to all three combined. Everything below Telnet is a rounding error.

MSSQL · 1433
6.30M
RDP · 3389
2.93M
VNC · 5901
1.90M
SSH · 22
1.88M
Telnet · 23
1.21M
REDIS · 6379
28.7K
FTP · MySQL · HTTP
<16K

Q1 was "Database Season." Q2 doubled down — MSSQL went from strong to dominant.

Daily connections · Apr 1 – Jun 30 (peak: 513K on 24 May)

Threat Actor Profiling

One library. One subnet.

The MSSQL flood isn't diverse. Two-thirds of it announces itself as go-mssqldb — a single Go database driver — and most of the volume comes from ten IPs in one coordinated /28.

MSSQL client library, by volume

go-mssqldb
4.29M
ODBC
1.41M
OLEDB
478K
.Net SqlClient
91K
DB-Library
14K

go-mssqldb at 68% of all MSSQL logins is a tooling fingerprint — a purpose-built Go scanner, not a mix of real clients.

Loudest IPsHits
119.8.10.250615,243MSSQL
104.192.6.74457,319MSSQL
180.103.117.65138,822MSSQL

194.113.39.0/28 — ten IPs, each firing ~423K MSSQL + ~66K RDP with near-identical volumes. Textbook coordinated infrastructure.

.2
396K SQL
70K RDP
.6
409K SQL
66K RDP
.10
410K SQL
66K RDP
.14
409K SQL
66K RDP
.18
410K SQL
66K RDP
.22
423K SQL
66K RDP
.26
423K SQL
66K RDP
.30
424K SQL
66K RDP
.34
423K SQL
66K RDP
.38
424K SQL
66K RDP

Combined: ~4.15M MSSQL + ~0.66M RDP = 4.81M from one /28 — roughly two-thirds of all MSSQL traffic this quarter.

Country Intelligence

The UK, out in front.

The June report caught UK infrastructure lighting up. Q2 confirms it: 5.13 million attacks from the UK — 1.8× the United States and more than the next four countries put together. It climbed all quarter and never let go.

Monthly attacks by source country · Apr → Jun 2026

UK · quarter
5.13M
#1 source · 36% of all traffic
UK · April → June
146K→2.61M
×18 climb across the quarter
United States
2.81M
#2 · steady all quarter
Mexico
691K
#4 · from 7K in April to 560K in June

These are hosting-provider footprints, not home nations — VPS and bulletproof capacity spun up where the campaign infrastructure lives.

Credential Analysis · Q2

Same keys. Every quarter.

Strip the MSSQL noise and the login attempts are the usual suspects: decade-old IoT defaults, botnet identifiers posing as usernames, and a VNC list that almost never matches.

SSH / Telnet · Mirai

The top credential pairs are verbatim Mirai/IoT defaults — hardcoded into botnets since 2016, still in constant rotation.

root / xc351180,630
root / vizxv72,704
root / admin65,001
admin / admin60,502
root / juantech40,625

xc3511, vizxv, juantech, xmhdipc — router/DVR defaults, ten years on.

RDP · Fingerprints

1.68M probes sent null — pure port checks. The named ones aren't people; they're tool identifiers.

null (probe)1,682,847
"35" (botnet ID)677,388
"hello" (botnet ID)385,647
"188" (botnet ID)78,365
Veeam · nmap · Sandratooling

Backup software and scanner names, baked into the kits.

VNC · Rarely matched

1.90M VNC handshakes; the DES response matched a known-weak password just 1.6% of the time (30,362). Those that did:

12345678902,596
password1231,440
1q2w3e4r783
iloveyou746
Password1740

98.4% never matched the common-password list at all.

Top password overall
admin
127,870 attempts
"root" username
980K
the real SSH brute-force target
VNC match rate
1.6%
30,362 of 1.90M handshakes
SMB Malware Capture

1,676 files.
One binary.

The SMB honeypots kept catching dropped files all quarter — and once the empty-length junk is thrown out, every real sample is the same executable: HackTool.RemoteExec / RemCom. The monoculture that has run for three years didn't break in Q2.

RemCom drops by sensor · Q2 2026

Sentinel
1,443
Armada
134
Digger
99

Sentinel is the sink — 86% of all captures, from 186K SMB events and 159K connects in Q2.

SHA1 · 23873bf2670cf64c2440058130548d4e4da412dd

RemCom — 100% of real drops

A remote-command execution tool abused as a lateral-movement payload. 1,676 identical copies written to the SMB shares this quarter — the attackers aren't diversifying, they're re-dropping the same kit.

Discarded as noise

Two other hashes appear — da39a3ee… and 8d451938… — both null-length artifacts, dropped from the count. Every non-empty file was RemCom.

SMB activity · Q2

~218K SMB events, ~189K connects, ~1,900 source IPs across the three nodes. Every captured file is submitted to VirusTotal.

The Sensors

Switzerland took the brunt.

Three live sensors shared the load, but not evenly — the Switzerland node absorbed half of everything on its own.

Switzerland
7.33M
US-West
4.11M
US-East
3.12M

What the quarter asks of everyone else:

Get MSSQL off the internet

44% of the quarter. Port 1433 belongs on a private network — never a public IP.

Kill default creds

Mirai defaults from 2016 still lead the list. Change them; use keys for SSH.

Watch SMB writes

RemCom lands via open shares. Restrict SMB, alert on executable drops.

Conclusion network visual

Q2 2026

Ninety-one days. The siege never lifted.

Nearly one knock in two went at a database.

One Go scanner and one /28 carried the flood.

And the same binary kept landing on the share.

0

Fourteen and a half million knocks, and almost half of them at one port. Q1 named it Database Season. Q2 turned it into a siege.

Next: Q3 2026.

The OpenCanary Experience →