Cứu em với!!!
Log trong ảnh:
2023-05-09 03:24:54.43 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:24:54.43 Logon Login failed for user 'faruk'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:25:06.41 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:25:06.41 Logon Login failed for user 'B01KSR2'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:25:12.90 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:25:12.90 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:25:23.36 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:25:23.36 Logon Login failed for user 'B01KSR3'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:25:32.34 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:25:32.34 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:25:42.57 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:25:42.57 Logon Login failed for user 'B02ADMIN'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:25:47.84 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:25:47.84 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:01.16 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:26:01.16 Logon Login failed for user 'B02KASIR'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:06.97 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:26:06.97 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:10.21 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:26:10.21 Logon Login failed for user 'agim'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:17.43 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:26:17.43 Logon Login failed for user 'B03ADMIN'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:22.02 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:26:22.02 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:37.32 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:26:37.32 Logon Login failed for user 'B03KASIR'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:41.42 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:26:41.42 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:52.13 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:26:52.13 Logon Login failed for user 'B04ADMIN'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:26:57.27 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:26:57.27 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:27:10.34 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:27:10.34 Logon Login failed for user 'B04KASIR'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:27:13.14 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:27:13.14 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:27:25.06 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:27:25.06 Logon Login failed for user 'burim'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:27:28.27 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:27:28.27 Logon Login failed for user 'B05ADMIN'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:27:33.03 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:27:33.03 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:27:45.48 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:27:45.48 Logon Login failed for user 'B05KASIR'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:27:48.12 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:27:48.12 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:05.68 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:28:05.68 Logon Login failed for user 'B06ADMIN'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:08.01 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:28:08.01 Logon Login failed for user 'parking'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:20.93 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:28:20.93 Logon Login failed for user 'B06KASIR'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:23.39 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:28:23.39 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:40.02 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:28:40.02 Logon Login failed for user 'senat'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:40.84 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:28:40.84 Logon Login failed for user 'B07ADMIN'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:42.15 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:28:42.15 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:56.91 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:28:56.91 Logon Login failed for user 'B07KASIR'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:28:58.62 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:28:58.62 Logon Login failed for user 'jinshi'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:29:14.43 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:29:14.43 Logon Login failed for user 'S0002'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:29:15.74 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:29:15.74 Logon Login failed for user 'webcitas'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:29:32.89 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:29:32.89 Logon Login failed for user 'S0003'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:29:32.94 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:29:32.94 Logon Login failed for user 'zhwj'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:29:49.29 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:29:49.29 Logon Login failed for user 'rpt'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:29:49.60 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:29:49.60 Logon Login failed for user 'S0004'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:29:54.94 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:29:54.94 Logon Login failed for user 'adnank'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:30:08.87 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:30:08.87 Logon Login failed for user 'sql'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:30:09.33 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:30:09.33 Logon Login failed for user 'GLOADMIN'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:30:24.20 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:30:24.20 Logon Login failed for user 'jero'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:30:24.99 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:30:24.99 Logon Login failed for user 'GLOKASIR'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:30:42.14 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:30:42.14 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:30:42.91 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:30:42.91 Logon Login failed for user 'ADM3'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:30:59.80 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:30:59.80 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:31:00.66 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:31:00.66 Logon Login failed for user 'ADMG1'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:31:09.87 Logon Error: 18456, Severity: 14, State: 5.
2023-05-09 03:31:09.87 Logon Login failed for user 'prod2'. Reason: Could not find a login matching the name provided. [CLIENT: 213.226.123.99]
2023-05-09 03:31:17.15 Logon Error: 18456, Severity: 14, State: 8.
2023-05-09 03:31:17.15 Logon Login failed for user 'sa'. Reason: Password did not match that for the login provided. [CLIENT: 213.226.123.99]
2023-05-09 03:31:18.15 Logon Error: 18456, Severity: 14, State: 5.
Máy đột nhiên bị chiếm nhiều RAM, dùng đến cả swap, kết quả sau khi chạy lệnh top
:
top - 11:34:07 up 94 days, 6:28, 1 user, load average: 0.37, 0.48, 0.31
Tasks: 417 total, 2 running, 415 sleeping, 0 stopped, 0 zombie
%Cpu(s): 7.5/8.6 16[||||||||||||||||| ]
MiB Mem : 79.7/9826.0 [|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| ]
MiB Swap: 43.3/3796.0 [||||||||||||||||||||||||||||||||||||||||||| ]
Lấy IP từ clien log faild thì ra kết quả IP Nga:
Có 2 IP cùng lớp mạng thay nhau Brute Force Attack là 213.226.123.99
và 213.226.123.98
Hiện tại nó vẫn đang scan nhưng em đã xóa hết data server rồi!