We have noticed that yesterday we had a load of failed login attempts in the Security event log on one of our Domain Controllers. An example is:
Event Type:Failure Audit
Event Source:Security
Event Category:Account Logon
Event ID:680
Date:11/12/2013
Time:7:44:52 AM
User:NT AUTHORITY\SYSTEM
Computer:NOR-DC-01
Description:
Logon attempt by:MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account:personal
Source Workstation:WBC-EX-01t
Error Code:0xC0000064
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
One of our Exchange 2010 servers is called WBC-EX-01, but these entries are coming from WBC-EX-01t, WBC-EX-01c, etc and from Logon accounts that don't exist.
Can anyone help as to what these are and if we can track down the source?
Thanks!!