Thousands of outgoi...
 
Notifications
Clear all

Thousands of outgoing RDP sessions

3 Posts
3 Users
0 Reactions
1,325 Views
(@slimbalato)
New Member
Joined: 8 years ago
Posts: 4
Topic starter  

Anyone know what would cause this in the logs? I suspect it's malware polling all of the nodes on the network but not sure of the method being used.


   
Quote
(@randomaccess)
Reputable Member
Joined: 13 years ago
Posts: 385
 

Sounds like malware. Would suggest looking at persistence mechanisms, running through malicious program execution and seeing what might be causing it.


   
ReplyQuote
(@deltron)
Estimable Member
Joined: 11 years ago
Posts: 125
 

What is the event ID ect.

Is it every minute/day/ect

Are they duplicate logs coming from different location?


   
ReplyQuote
Share: