We recently noticed (by using Active Directory auditing) strange login attempts that are being made by many of our workstations. Is this a virus/worm? If so, how can I know which one is it?
hi,
recently noticed (by using active directory auditing tool) strange login attempts many workstations on our corporate network, of these login attempts use strange usernames not exist on our active directory (such @@cyaaaaajbgca0gahbaza0gapbgbaaeazbwdaeda, owner, support_388945a0 , others) see extremely high rate (over hundred attempts per second single workstation) of login attempts supposedly made legitimate users wrong passwords.
how can tell if virus/worm , if 1 or how remove it?
btw: didn't mentioned because sort of given thing - have trendmicro antivirus installed , running on of our workstations , up-to-date. have up-to-date wsus server.
thanks lot,
yuval.
yuvalk
hi same problem faced few years and so here's do. run port reporter service awhile, couple of hours let's say. depending on volume of entries/size, create more 1 log file (they have date time ranges in filenaming convention). the logs fill kinds of traffic details, every browser request, of it, can big fast on busy machine. look in event log clusters of 529s wish investigate. now open pr parser , open port reporter logfile covers period of time. now you, exact same datetimestamp entries, more that, can use pr parser apply criteria to highlight entries of particular type. you first have edit criteria settings, suggest on ports tab add <portnumber> udp , tcp using terminal services (the default remote desktop 3389). that way, when apply criteria, entries highlighted in red. you can aslo edit, filters, filter data. in way can relate 529 errors seeing in event log originating ip. you can go far email abuse dept of originating isp have customer either hacking or infected, that's bit of "blowing in windstorm" though.
don't forget turn off port reporter service or else manage , delete old logs regularly or else you'll filling hard disk logs.
i hope i'm solutions.
Windows Server > Directory Services
Comments
Post a Comment