Hi experts
i am getting events flooded with 4625 and 4776 in audit failures
when i login to Server30 i can see the eventID's 4625 and 4776, Server30 is in domain xyz.com where as server20 is in domain abc.com
The account server20$ doesnot exist at all.server20 is accessing Server30 with someother account but there is no account by name server20$.
how do i troubleshoot this
Event ID 4625
An account failed to log on.
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: Server20$
Account Domain:abc.com
Failure Information:
Failure Reason:Unknown user name or bad password.
Status: 0xC000006D
Sub Status: 0xC0000064
Process Information:
Caller Process ID:0x0
Caller Process Name:-
Network Information:
Workstation Name:Server20
Source Network Address:192.168.1.1
Source Port: 98765
Detailed Authentication Information:
Logon Process:NtLmSsp
Authentication Package:NTLM
Transited Services:-
Package Name (NTLM only):-
Key Length: 0
-----------------------------------------
Event ID 4776
The computer attempted to validate the credentials for an account.
Authentication Package:MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account:Server20$
Source Workstation:Server20
Error Code:0xC000006
i am getting events flooded with 4625 and 4776 in audit failures
when i login to Server30 i can see the eventID's 4625 and 4776, Server30 is in domain xyz.com where as server20 is in domain abc.com
The account server20$ doesnot exist at all.server20 is accessing Server30 with someother account but there is no account by name server20$.
how do i troubleshoot this
Event ID 4625
An account failed to log on.
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: Server20$
Account Domain:abc.com
Failure Information:
Failure Reason:Unknown user name or bad password.
Status: 0xC000006D
Sub Status: 0xC0000064
Process Information:
Caller Process ID:0x0
Caller Process Name:-
Network Information:
Workstation Name:Server20
Source Network Address:192.168.1.1
Source Port: 98765
Detailed Authentication Information:
Logon Process:NtLmSsp
Authentication Package:NTLM
Transited Services:-
Package Name (NTLM only):-
Key Length: 0
-----------------------------------------
Event ID 4776
The computer attempted to validate the credentials for an account.
Authentication Package:MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account:Server20$
Source Workstation:Server20
Error Code:0xC000006