My newly acquired windows 2008 virtual server now has 3.500 entries (in three days) in its security log, most of which are of event ID 4625: "An account failed to log on".
The login attempts appear rather quick - about 10-20 attempts per second. I guess this is an attack - is that correct?
It does not appear as if the attacker (I'll just use this name) was successful in logging in and brute-forcing the password should not be easy since it is long and complicated...
However, I wonder whether there is something I can do systematically? How about changing the port of rdp? A hardware firewall will probably help?
Moreover, the server now hosts only a single website which is not even public yet, so I didn't expect any traffic of this kind so soon. A little vague: will this get much worse when the site goes online?