Abuse from:

Status
Not open for further replies.

HTCsecurity

New User
Joined
Sep 25, 2020
Messages
14
Reaction score
2
I'm getting emails from EGP saying my server is "Caught scanning for web/mail exploits / compromised hosts" and is delisting it.
These load is running on a PI 4 and I have reloaded twice with a clean version of Raspbian and restored the configuration from a back up but this keeps happening.
the report is very long but here is clip of what its saying.
Any help would be very thankful.
(I removed IP to help keep privet)

Current EGP Cloudblock RBL listings in xxx.xx.xxx.xxx/32:

----------------------------------------------------------------------------------------------------

xxx.xx.xxx.xxx/32: Caught scanning for web/mail exploits / compromised hosts [strike 2: 3 day minimum] @@1623025225

To whom it may concern,


To whom it may concern,



xxx.xx.xxx.xx is reported to you for performing unwanted activities toward our server(s).



=============================================================================

Current records of unwanted activities toward our server(s) on file; the second field designates our server that received the unwanted connection; if this is a webserver log, the [VirtualHost] designates the visited website.

-----------------------------------------------------------------------------

*xxx.xx.xxx.xx tpc-005.mach3builders.nl 20210607/02:20:26 02:20:16.266638 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx .11535 > 91.xxx.xx.xxx.xx: Flags , seq 2328796875, win 0, options [mss 1460], length 0

* xxx.xx.xxx.xx tpc-005.mach3builders.nl 20210607/02:20:25 02:20:16.179306 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.27346 > 91.190.98.169.22: Flags , seq 484423940, win 0, options [mss 1460], length 0

* xxx.xx.xxx.xx tpc-005.mach3builders.nl 20210531/20:09:02 20:09:01.109001 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.64658 > 91.190.98.95.22: Flags , seq 2532920862, win 0, options [mss 1460], length 0

* xxx.xx.xxx.xx alai.FreeBSD.org 20210531/19:25:01 12:24:51.545403 rule 0/0(match): block in on xn0: xxx.xx.xxx.xx.54839 > 204.109.59.195.22: Flags , seq 908588616, win 65535, length 0

* xxx.xx.xxx.xx tpc-024.mach3builders.nl 20210530/03:08:37 03:08:32.152565 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.1852 > 91.190.98.192.22: Flags , seq 4067915226, win 0, options [mss 1460], length 0

* xxx.xx.xxx.xx tpc-004.mach3builders.nl 20210528/10:34:55 10:34:45.236955 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.56605 > 91.190.98.199.22: Flags , seq 4277603540, win 0, options [mss 1460], length 0

is reported to you for performing unwanted activities toward our server(s).



=============================================================================

Current records of unwanted activities toward our server(s) on file; the second field designates our server that received the unwanted connection; if this is a webserver log, the [VirtualHost] designates the visited website.

-----------------------------------------------------------------------------

* xxx.xx.xxx.xx tpc-005.mach3builders.nl 20210607/02:20:26 02:20:16.266638 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.11535 > 91.190.98.169.22: Flags , seq 2328796875, win 0, options [mss 1460], length 0

* xxx.xx.xxx.xx tpc-005.mach3builders.nl 20210607/02:20:25 02:20:16.179306 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.27346 > 91.190.98.169.22: Flags , seq 484423940, win 0, options [mss 1460], length 0

* xxx.xx.xxx.xx tpc-005.mach3builders.nl 20210531/20:09:02 20:09:01.109001 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.64658 > 91.190.98.95.22: Flags , seq 2532920862, win 0, options [mss 1460], length 0

* xxx.xx.xxx.xx alai.FreeBSD.org 20210531/19:25:01 12:24:51.545403 rule 0/0(match): block in on xn0: xxx.xx.xxx.xx.54839 > 204.109.59.195.22: Flags , seq 908588616, win 65535, length 0

* xxx.xx.xxx.xx tpc-024.mach3builders.nl 20210530/03:08:37 03:08:32.152565 rule 0/0(match): block in on vmx0: xxx.xx.xxx.xx.1852 > 91.190.98.192.22: Flags , seq 4067915226, win 0, options [mss 1460], length 0

* xxx.xxx.xxx.xxx tpc-004.mach3builders.nl 20210528/10:34:55 10:34:45.236955 rule 0/0(match): block in on vmx0:xxx.xx.xxx.xx.56605 > 91.190.98.199.22: Flags , seq 4277603540, win 0, options [mss 1460], length 0
 
Last edited:
Hi @HTCsecurity,

It sounds like this is a security issue, and this forum is specific to 3CX matters. If this is a clean Raspbian image, I'd suggest asking on the Raspbian forum.

What else is behind your Public IP? What made you sure that it is specifically the Pi and not something else on your network? What backup did you restore?

Why not take the Pi offline and check if the attacks continue to happen?
 
When you say "reloaded raspian" - have you done it the official way?

https://www.3cx.com/docs/installing-pbx-raspberry-pi/

What makes you think it's the Pi?

If you have more then 1 device behind a NAT router then it could be any of them and I would start running antivirus scans.
 
the attacks seem to follow this unit I have moved it to another location and another IP after I reimaged it and did a restore of the 3CX backup in order to get software back on line.
I followed the "Official way" each time to be sure not to make a mistake or get something from some where I should not.
I just got this message from my provider also.

""Invalid user pi from xxx.xxx.xxx.xxx port 50364 Jun 4 07:29:00 dns01 sshd[1878556]: Invalid user pi from xxx.xxx.xxx.xxx port 48434 Jun 4 07:29:00 dns01 sshd[1878555]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=xxx.xxx.xxx.xxx Jun 4 07:29:00 dns01 sshd[1878556]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=xxx.xxx.xxx.xxx Jun 4 07:29:02 dns01 sshd[1878555]: Failed password for invalid user pi from xxx.xxx.xxx.xxx port 50364 ssh2 Jun 4 07:29:02 dns01 sshd[1878556]: Failed password for invalid user pi from xxx.xxx.xxx.xxx port 48434 ssh2""

should the only ports that i have open to the outside world be

Port 5090 (inbound, UDP and TCP) for the 3CX tunnel.
Port 443 or 5001 (inbound, TCP) HTTPS for Presence and Provisioning, or the custom HTTPS port you specified.
Port 443 (outbound, TCP) for Google Android Push.
Port 443, 2197 and 5223 (outbound, TCP) for Apple iOS Push

if so what about the ones it checks with the "Firewall checker"
  • resolving 'stun-us.3cx.com'... done
  • resolving 'stun2.3cx.com'... done
  • resolving 'stun3.3cx.com'... done
  • resolving 'sip-alg-detector.3cx.com'... done
  • testing 3CX SIP Server... done
    • stopping service... done
    • detecting SIP ALG... not detected
    • testing port 5060... done
    • starting service... done
  • testing 3CX Tunneling Proxy... done
    • stopping service... done
    • testing port 5090... done
    • starting service... done
testing 3CX Media Server... done
testing ports [9000..9398] (all ... done)
testing ports [10600..10998] (all ... done)
 
Last edited:
Have you been installing anything else on the Pi?
 
Hi @HTCsecurity,

Without isolating the traffic of the device itself to the firewall and the firewall to the internet (LAN and WAN interfaces), we're not confirming that it is, in fact, the Pi that is sending the malicious traffic. I'd suggest running a wireshark capture and isolating traffic from that IP and MAC address to confirm that it is in fact the Pi that is sending the traffic being reported to you.

When you said you ran a "restored the configuration from a back up" to which configuration do you refer?
 
Last edited:
3CX is the only thing that is running or installed besides the OS
My plan today is to setup up another with a different account just like this one and install at a different IP and see if it gets attacked
 
Hello,
From the second log snippet you provided it looks like an SSH access is being brute-forced by untrusted parties.
Is that taken from the syslog of your raspberry?
You should ensure having set strong credentials for the Linux "pi" user, and perhaps restrict by firewall which IP addresses are allowed to reach that port, i.e should be those of your trusted administrators only.

The IP address mentioned is well known in the AbuseIPDB as scanning around: https://www.abuseipdb.com/check/216.16.181.58
 
  • Like
Reactions: VasilisV_3CX
Hello,
From the second log snippet you provided it looks like an SSH access is being brute-forced by untrusted parties.
Is that taken from the syslog of your raspberry?
You should ensure having set strong credentials for the Linux "pi" user, and perhaps restrict by firewall which IP addresses are allowed to reach that port, i.e should be those of your trusted administrators only.

The IP address mentioned is well known in the AbuseIPDB as scanning around: https://www.abuseipdb.com/check/x
it came from Fail2Ban ,

do we need to SSH on port 22 open
With the post above I listed the ports as what we have open, can you confirm what needs to open through the firewall
 
Did you ever change the pi ssh password until now or is the default that comes with the disk image?

user: pi
password: raspberry
 
Did you ever change the pi ssh password until now or is the default that comes with the disk image?

user: pi
password: raspberry
It was changed,, but I will check to reconfirm because I had others working on it also.
 
  • Like
Reactions: VasilisV_3CX
Status
Not open for further replies.