Solved Hacked overnight

Status
Not open for further replies.

comsyco-gavin

Silver Partner
Joined
Mar 25, 2022
Messages
34
Reaction score
8
Good Morning

One of our clients appear to have been hacked overnight .. We got notified by our trunk provider who gave us the times of the hack , when looking at the call logs it appears one extension was used to repeatedly make random calls , most failing but then every so often it looks like an external number has rang another external number. Screenshots of call log and more importantly call report below:

calllog.png
callreport.png
I am just wondering if anyone can shed any light as to what is happening on these calls.

I have regenerated the user extension, changed the phone password and re provisioned and the trunk pwd has been reset, scanned the users machine (it was off overnight so I don't believe it came from there.)

Is there anything else that people can think to do or have I covered bases, is there anything that our provider could maybe look to do to restrict access to that trunk maybe location wise ? ... our management is restricted to our internal IP range through VPN with no other access allowed

Unfortunately our activity logs were only set to low so unable to really get much information in that regards
 
I suspect a conference call was set up. Have you checked at an OS level to see if you've been breached there?
 
The OS seems to be fine from what I can tell and there were no attempts to get at the server direct at all overnight , I did suspect a conference call is what was set up.
 
@comsyco-gavin
Hi there.
User extension 300, is the one that only was placing the calls?
If the PBX was in verbose logging you could search to identify IPs used, and how it was placing the calls.
Also ensure that email access to that user is also changed, as maybe the email was compromised too.
Additionally, here is the blogpost from our security team member that will help you to protect your system as a whole. There are 4 volumes, and I will advise you to check them all.
 
  • Like
Reactions: ms38
Thanks for your response

Yes ext 300 was the only one trying to make calls .. unfortunately it was not in verbose mode so tracing like that is not a possibility
 
There is nothing much you can then check in the logs, but after you change the passwords on the 3CX end, ensure that you change the password on the email that the extension used. Also, see our guide above.
 
There is nothing much you can then check in the logs, but after you change the passwords on the 3CX end, ensure that you change the password on the email that the extension used. Also, see our guide above.
This was done as matter of course first thing and dealt with at customer end , thanks for your responses though confirming there isnt really much I can dig to find out any more , nothing has happened overnight today so hopefully that will be the end of that ! This time anyway lol
 
Thank you for the feedback too.
Have a nice day
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,991
Messages
590,166
Members
164,929
Latest member
Cloudstar