OK, definitely is the RDP port...
Many ransomware use it to hack Servers.
Use some RDP security software or, better, don't open RDP.
Gabriele Maoret - Head of SysAdmins at SERSIS
Currently manages 6 SmarterMail installations (1 in the cloud for SERSIS which provides services to a few hundred third-party email domains + 5 on-premise for customers who prefer to have their mail server in-house)