Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

ASUS RT-AC5300 - Is anyone else logged in or trying to Brute force in?


  • Please log in to reply
61 replies to this topic

#16 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:19 AM

Posted 11 August 2024 - 06:23 PM

I don't use RDP. My IT guy connects to my laptop when needed, but it doesn't use windows login. I have to authorize him when it pops up on my screen. I'm the only one using this laptop here.



BC AdBot (Login to Remove)

 


#17 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 06:37 PM

Do the Event Log entries show the IP address of the client device that tried to logon?


- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#18 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:19 AM

Posted 11 August 2024 - 06:38 PM

They do not.



#19 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 06:43 PM

We could ask you more questions about your event log entries, but what might be easier would be if you Exported your Security and System logs and uploaded the .evtx files here for us to look at. You could send them privately by IM so no one other than the helpers here could see them.


- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#20 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:19 AM

Posted 11 August 2024 - 06:52 PM

Sure. I can send them privately. Would I be sending them to you? How would the other helpers see them?



#21 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 06:54 PM

You could start by sending them to me. Remember, I'm not looking for .txt files, but .evtx files. The latter we can open directly in Event Viewer, where we can filter and read them much more easily.


Edited by Shplad, 11 August 2024 - 07:20 PM.

- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#22 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:19 AM

Posted 11 August 2024 - 06:55 PM

I have already exported them. Waiting to send. Can't add attachments to IM's?



#23 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 07:37 PM

-ignore-


Edited by Shplad, 11 August 2024 - 07:39 PM.

- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#24 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:19 AM

Posted 11 August 2024 - 07:40 PM

No. Not at all. I didn't touch the user accounts let alone assign privlages

 

Though today, I'm logged in with my user name (Administrator priviledge) and I tried going into a folder to which it said that I need admin priv to view, would you like to view it? Yes, then it said to click yes to allow me to view it. Was weird.



#25 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 07:43 PM

That is perfectly normal behaviour. It's Windows way of verifying you're not malware trying to make changes. 


- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#26 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 07:46 PM

Back to the event logs, here's what I got from Perplexity.ai when I asked if it was normal get failed logon attempts via the Guest account:

 

It is not normal for Windows event logs to consistently show failed logons via the Guest account, especially when the account is disabled. This behavior can indicate various issues:

In summary, while occasional failed logon attempts might happen under specific conditions, a high number of such events, especially when the Guest account is disabled, is not typical and should be investigated to ensure there are no security vulnerabilities or misconfigurations in the network.

  1. Network Connections: Failed logon attempts using the Guest account can occur due to network connections, especially if a shared folder includes permissions for "Everyone," which might trigger attempts to access the share using the Guest account.
  2. Internal Network Activity: Such logon failures might originate from within the internal network, suggesting that an unknown computer or service is attempting to access resources on the server.
  3. External Access Attempts: If the server is exposed to the internet, such as having open ports for Remote Desktop Protocol (RDP), it might be subject to brute force attacks or unauthorized access attempts, resulting in numerous failed logon attempts
  4. subject to brute force attacks or unauthorized access attempts, resulting in numerous failed logon attempts.
  5. Configuration or Monitoring Tools: Monitoring tools or misconfigured services might inadvertently trigger these logon attempts. For example, certain security tools or scripts might attempt to validate credentials using the Guest account, leading to these logs

 

In summary, while occasional failed logon attempts might happen under specific conditions, a high number of such events, especially when the Guest account is disabled, is not typical and should be investigated to ensure there are no security vulnerabilities or misconfigurations in the network.

 


Edited by Shplad, 11 August 2024 - 07:47 PM.

- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#27 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 07:50 PM

Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          8/11/2024 9:30:54 AM
Event ID:      5058
Task Category: Other System Events
Level:         Information
Keywords:      Audit Success
User:          N/A
Computer:      Dov
Description:
Key file operation.
 
Subject:
Security ID: SYSTEM
Account Name: USERFIRSt$
Account Domain: LASTNAME
 
Logon ID: 0x3E7
Process Information:
Process ID: 3280
Process Creation Time: ‎2024‎-‎08‎-‎11T01:16:28.634173000Z
 
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: ESET encryption key
Key Type: Machine key.
 
Key File Operation Information:
File Path: C:\ProgramData\Microsoft\Crypto\Keys\05bfb2b62daf9420edc8c71057ae114c_b514bf88-93d2-488c-869b-283048e9441c
Operation: Read persisted key from file.
Return Code: 0x0
Event Xml:
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <EventID>5058</EventID>
    <Version>1</Version>
    <Level>0</Level>
    <Task>12292</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8020000000000000</Keywords>
    <TimeCreated SystemTime="2024-08-11T13:30:54.5385302Z" />
    <EventRecordID>2182907</EventRecordID>
    <Correlation ActivityID="{0c1fd9ad-eb8c-0002-3cda-1f0c8cebda01}" />
    <Execution ProcessID="1080" ThreadID="1816" />
    <Channel>Security</Channel>
    <Computer>Dov</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="SubjectUserSid">S-1-5-18</Data>
    <Data Name="SubjectUserName">USERFIRST$</Data>
    <Data Name="SubjectDomainName">LASTNAME</Data>
    <Data Name="SubjectLogonId">0x3e7</Data>
    <Data Name="ClientProcessId">3280</Data>
    <Data Name="ClientCreationTime">2024-08-11T01:16:28.6341730Z</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">ESET encryption key</Data>
    <Data Name="KeyType">%%2499</Data>
    <Data Name="KeyFilePath">C:\ProgramData\Microsoft\Crypto\Keys\CryptoKeyValue</Data>
    <Data Name="Operation">%%2458</Data>
    <Data Name="ReturnCode">0x0</Data>
  </EventData>
</Event>

- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#28 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:19 AM

Posted 11 August 2024 - 07:50 PM

Well that's not good. Something that I was suspecting. #2. Can be ruled out as there is no internal network here. It's just me.

How do we pinpoint this? Not really feeling comfortable here.



#29 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:19 AM

Posted 11 August 2024 - 07:52 PM

What's this?



#30 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,824 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:08:19 AM

Posted 11 August 2024 - 07:55 PM

What's this?

That post is blank.

 

I see nothing obvious here yet, though I'm not a security expert. Dan? Are you around? 

I'm still browsing through your event logs.


- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 





2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users