Abstract digital connections background

The OpenCanary Experience · Wall of Fame

176 million knocks. 903 days. The all-time record board.

Three and a half years of canaries on the open internet, every chart-topper in one place — the ports, the countries, the credentials, and the one file that just won't stop coming.

Scroll, swipe, or use the arrow keys.

The records · 11 Oct 2023 → 31 Mar 2026

The headline numbers.

Total connections
0
across 903 days
Per hour, non-stop
~8,100
~194,953 every day
Biggest single day
0
23 August 2024
New source IPs
~1.44M
first-seen across the run
Biggest single attacker
0
220.120.147.167 (Korea), 2024 alone
Fastest first knock
10 sec
after going live, 11 Oct 2023
Most-dropped file
RemCom
~39,000 times · 99.96% of all malware
Distinct malware binaries
3
in three and a half years

Hall of fame · ports

What the internet hammered.

MSSQL · 143357,881,036
RDP · 338954,673,289
SSH · 2238,873,247
VNC · 590118,104,043
Telnet · 234,725,409
Redis · 63791,096,364
MySQL · 3306339,236
FTP · 21256,799
HTTP · 8092,443

MSSQL took the crown

Across the whole run the database (port 1433) narrowly overtook RDP as the single most-targeted service — 57.9M to 54.7M. Remote access still rules in aggregate (66%), but the trend points at your data.

Who knocked on 1433

By client fingerprint: ODBC 43.2M · bare/blank probe 8.9M · OLEDB 3.5M · .Net SqlClient 1.4M · go-mssqldb 561K.

Hall of fame · geography

Where it came from.

#CountryAttacks
1United States28,285,672
2China20,047,211
3South Korea15,279,916
4Germany12,203,471
5Netherlands11,103,670
6Russia10,830,792
7Belgium10,234,581
8Romania7,738,865

A rotating cast: the US and China lead every year, but the supporting acts change — Korea and Belgium surged in 2024, Romania and a one-quarter Turkish flood (4.7M) drove 2026.

Hall of shame · source IPs

The worst offenders.

Source IPProfileConnections
220.120.147.167South Korea · the all-time monster10,659,664
92.86.69.77Romania · 2026 MSSQL flood7,549,865
202.58.95.8heavy scanner3,890,328
198.154.94.70heavy scanner2,091,457
185.73.125.23the perennial VNC offender1,409,511
104.192.6.74the perennial MSSQL prober1,218,876

A single host — 220.120.147.167 — accounts for more knocks than most countries.

Hall of fame · credentials

The keys they tried most.

🦠 Top credential pairs

UsernamePasswordAttempts
adminadmin627,939
rootroot107,675
rootadmin100,463
root12345681,798
rootvizxv78,481
rootxc351172,294

Top passwords

123456 965,592 · admin 796,354 · 1234 267,231 · 123 254,672 · password 238,753 · 12345 198,001

Top usernames

null 26.9M · root 9.47M · hello 8.12M · administr… 3.01M · admin 2.02M

Hall of fame · the file share

One tool, ~39,000 times.

Files received (est.)
~39,600
incl. log-reconstructed 2024
RemCom share
99.96%
of all real malware
Distinct binaries
3
in three and a half years
SMB events
6,915,582
logged across the sensors
Every malware hash ever caught
23873bf2…412dd  ·  ~39,000×
RemCom · HackTool.RemoteExec — the same binary since Genesis 2023.
8d451938…fb590  ×8  repack of 3c2fe308… — same size, new signature
abd5d6cc…d735  ×1  Trojan.MSIL/Blocker

Every byte that landed went to VirusTotal. The internet dropped its break-in tool on the share ~39,000 times — and it was almost always the exact same file.

Conclusion network visual

Wall of Fame

176 million knocks — and counting.

The aim narrowed from desktops to databases.

A handful of IPs out-knock whole nations.

The same password and the same file, every year.

0

Connection attempts on three canaries, since 11 October 2023. The board keeps growing.

The OpenCanary Experience →