cancel
Showing results for 
Search instead for 
Did you mean: 

strange workstation name(lQPxf2ISQgEV1bGK) tries to login to my servers

fida
Level 2

Hi,

I'm having issues and worried as this unknown system that continuesly tries to connect to my W2K3 servers. Recently one of my admin account was locked out on 2 of my servers and stopped important services and these servers are having these logs continuesly. could this happened because of these logs ?

this is one of the Windows Server 2003 security log files:

event ID: 529
type:  failure audit
source: NT AUTHORITY/SYSTEM
catagory: logon/logoff

Reason: Unknown user name or bad password

User Name:

Domain: WORKGROUP

Logon Type: 3

Logon Process: NtLmSsp

Authentication Package: NTLM

Workstation Name: lQPxf2ISQgEV1bGK

Caller User Name: -

Caller Domain: -

Caller Logon ID: -

Caller Process ID: -

Transited Services: -

Source Network Address:

Source Port: 0

 

Strange thing is it keeps changing IP addresses but they are all my companies ip address

Have any one have seen this before ..please help     Thanks

1 REPLY 1

Thomas_K
Level 6

Read this entry on the Internet Storm Center site - http://isc.sans.org/diary.html?date=2009-04-16