Server 2003 – Event Viewer 540 Anonymous Logon from strange IPs

windows-event-logwindows-server-2003

The Event Viewer for my Windows Server 2003 machine is flooded with these 540 login attempts from IP addresses in foreign countries. It looks like somebody is trying to access my machine – what sort of logon attempt could this be?

Is there anything I can do besides blocking the subnet with my hardware firewall?

Successful Network Logon:
User Name:  
Domain:     
Logon ID:       (0x0,0xAFB92F)
Logon Type: 3
Logon Process:  NtLmSsp 
Authentication Package: NTLM
Workstation Name:   MATE-5BAD844B02
Logon GUID: -
Caller User Name:   -
Caller Domain:  -
Caller Logon ID:    -
Caller Process ID: -
Transited Services: -
Source Network Address: 84.2.197.145
Source Port:    0

Best Answer

Event ID 540 for Logon Type 3 is a successfull network logon. Do you have IIS installed on the server running a publicly accessible web site? If so, that's the most likely source of the logons.

Related Topic