- Joined
- Nov 12, 2010
- Messages
- 4
- Reaction score
- 0
Strangely, yesterday I ran out of balance for my international calls. I checked my logs and notice my main extension 100 had made about 20 calls in a span of 30 minutes running out my balance. Since it was yesterday I wasn't able to get any server logs.
Then just now I received an email from my trunk provider that my credit card has been recharged for a new balance since it ran out. Note, I had just recharged it earlier this morning.
I checked my logs and found that 17 new calls that sucked up my balance dry calling to "0023222272359", a destination in Sierra Leone Freetown. It was the same destination as yesterday. The other one being "0020106699703", a destination to Egypt Mobile.
It seems my system has been compromise for Vishing as googling reveals.
The calls are being made from an extension 100 which is the phone sitting right in front of me. It hasn't been used so I checked the 3cx logs immediately and found the following below.
19:21:26.171 [CM503001]: Call(412): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:21:07.171 [CM503008]: Call(411): Call is terminated
19:21:07.156 [CM503008]: Call(411): Call is terminated
19:20:53.218 [CM503008]: Call(409): Call is terminated
19:20:53.218 [CM503008]: Call(409): Call is terminated
19:19:37.671 [CM503007]: Call(411): Device joined: sip:[email protected]:5060
19:19:37.656 [CM503007]: Call(411): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:19:37.281 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:19:37.265 [CM503002]: Call(411): Alerting sip:[email protected]:5060
19:19:34.734 [CM503004]: Call(411): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:19:34.703 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:19:34.687 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:19:34.671 [CM503001]: Call(411): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:19:16.500 [CM503008]: Call(410): Call is terminated
19:19:16.500 [CM503008]: Call(410): Call is terminated
19:17:44.953 [CM503007]: Call(410): Device joined: sip:[email protected]:5060
19:17:44.937 [CM503007]: Call(410): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:17:44.421 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:44.406 [CM503002]: Call(410): Alerting sip:[email protected]:5060
19:17:41.875 [CM503004]: Call(410): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:17:41.843 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:17:41.828 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:17:41.812 [CM503001]: Call(410): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:17:24.859 [CM503008]: Call(408): Call is terminated
19:17:24.828 [CM503008]: Call(408): Call is terminated
19:17:24.796 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:20.953 [CM503007]: Call(409): Device joined: sip:[email protected]:5060
19:17:20.937 [CM503007]: Call(409): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:17:20.500 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:20.484 [CM503002]: Call(409): Alerting sip:[email protected]:5060
19:17:18.140 [CM503004]: Call(409): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:17:18.109 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:17:18.093 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:17:18.078 [CM503001]: Call(409): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:17:08.468 [CM503007]: Call(408): Device joined: sip:[email protected]:5060
19:17:08.453 [CM503007]: Call(408): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:17:07.984 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:07.968 [CM503002]: Call(408): Alerting sip:[email protected]:5060
19:17:05.703 [CM503004]: Call(408): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:17:05.671 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:17:05.671 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:17:05.640 [CM503001]: Call(408): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:17:05.640 [MS101003] C:408.1: Possible firewall problem. Address mapping failed on STUN server 75.101.138.128:3478 for local address ":9000"
19:17:05.640 [MS201000] Use STUN server 'stun2.3cx.com:3478'
19:17:05.640 [MS101005] STUN request failed for ports 9000,9001 on STUN server 'stun.3cx.com:3478'
19:17:05.515 [MS201000] Use STUN server 'stun.3cx.com:3478'
19:17:05.515 [MS101005] STUN request failed for ports 9000,9001 on STUN server 'stun2.3cx.com:3478'
19:17:05.406 [MS201000] Use STUN server 'stun2.3cx.com:3478'
19:17:05.375 [MS101005] STUN request failed for ports 9000,9001 on STUN server 'stun.3cx.com:3478'
19:16:50.125 [CM503008]: Call(407): Call is terminated
19:16:50.125 [CM503008]: Call(407): Call is terminated
19:16:40.078 [CM503008]: Call(406): Call is terminated
19:16:40.078 [CM503008]: Call(406): Call is terminated
19:10:16.718 [CM503007]: Call(407): Device joined: sip:[email protected]:5060
19:10:16.703 [CM503007]: Call(407): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
First of all, I've block all outgoing international calls for now but can someone suggest me a simple solution to stop this? Perhaps turning off stun? Changing the port for stun? I had set it up for external extensions but our off site sales guy is gone and that feature is no longer needed. How can I easily stop this because I dont' want to bleed any more money for these SOBs.
Then just now I received an email from my trunk provider that my credit card has been recharged for a new balance since it ran out. Note, I had just recharged it earlier this morning.
I checked my logs and found that 17 new calls that sucked up my balance dry calling to "0023222272359", a destination in Sierra Leone Freetown. It was the same destination as yesterday. The other one being "0020106699703", a destination to Egypt Mobile.
It seems my system has been compromise for Vishing as googling reveals.
The calls are being made from an extension 100 which is the phone sitting right in front of me. It hasn't been used so I checked the 3cx logs immediately and found the following below.
19:21:26.171 [CM503001]: Call(412): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:21:07.171 [CM503008]: Call(411): Call is terminated
19:21:07.156 [CM503008]: Call(411): Call is terminated
19:20:53.218 [CM503008]: Call(409): Call is terminated
19:20:53.218 [CM503008]: Call(409): Call is terminated
19:19:37.671 [CM503007]: Call(411): Device joined: sip:[email protected]:5060
19:19:37.656 [CM503007]: Call(411): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:19:37.281 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:19:37.265 [CM503002]: Call(411): Alerting sip:[email protected]:5060
19:19:34.734 [CM503004]: Call(411): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:19:34.703 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:19:34.687 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:19:34.671 [CM503001]: Call(411): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:19:16.500 [CM503008]: Call(410): Call is terminated
19:19:16.500 [CM503008]: Call(410): Call is terminated
19:17:44.953 [CM503007]: Call(410): Device joined: sip:[email protected]:5060
19:17:44.937 [CM503007]: Call(410): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:17:44.421 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:44.406 [CM503002]: Call(410): Alerting sip:[email protected]:5060
19:17:41.875 [CM503004]: Call(410): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:17:41.843 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:17:41.828 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:17:41.812 [CM503001]: Call(410): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:17:24.859 [CM503008]: Call(408): Call is terminated
19:17:24.828 [CM503008]: Call(408): Call is terminated
19:17:24.796 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:20.953 [CM503007]: Call(409): Device joined: sip:[email protected]:5060
19:17:20.937 [CM503007]: Call(409): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:17:20.500 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:20.484 [CM503002]: Call(409): Alerting sip:[email protected]:5060
19:17:18.140 [CM503004]: Call(409): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:17:18.109 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:17:18.093 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:17:18.078 [CM503001]: Call(409): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:17:08.468 [CM503007]: Call(408): Device joined: sip:[email protected]:5060
19:17:08.453 [CM503007]: Call(408): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
19:17:07.984 [CM505003]: Provider:[CallCentric] Device info: Device Not Identified: User Agent not matched; Capabilities:[reinvite, replaces, able-no-sdp, recvonly] UserAgent: [] Transport: [sip:192.168.1.70:5060]
19:17:07.968 [CM503002]: Call(408): Alerting sip:[email protected]:5060
19:17:05.703 [CM503004]: Call(408): Calling: VoIPline:0023222272359@(Ln.10002@CallCentric)@[Dev:sip:[email protected]:5060]
19:17:05.671 [CM503010]: Making route(s) to "0023222272359"<sip:[email protected]>
19:17:05.671 [CM505001]: Ext.100: Device info: Device Identified: [Man: Counterpath;Mod: eyeBeam;Rev: General] Capabilities:[reinvite, no-replaces, unable-no-sdp, recvonly] UserAgent: [eyeBeam release 1010f stamp 39239] Transport: [sip:192.168.1.70:5060]
19:17:05.640 [CM503001]: Call(408): Incoming call from Ext.100 to "0023222272359"<sip:[email protected]>
19:17:05.640 [MS101003] C:408.1: Possible firewall problem. Address mapping failed on STUN server 75.101.138.128:3478 for local address ":9000"
19:17:05.640 [MS201000] Use STUN server 'stun2.3cx.com:3478'
19:17:05.640 [MS101005] STUN request failed for ports 9000,9001 on STUN server 'stun.3cx.com:3478'
19:17:05.515 [MS201000] Use STUN server 'stun.3cx.com:3478'
19:17:05.515 [MS101005] STUN request failed for ports 9000,9001 on STUN server 'stun2.3cx.com:3478'
19:17:05.406 [MS201000] Use STUN server 'stun2.3cx.com:3478'
19:17:05.375 [MS101005] STUN request failed for ports 9000,9001 on STUN server 'stun.3cx.com:3478'
19:16:50.125 [CM503008]: Call(407): Call is terminated
19:16:50.125 [CM503008]: Call(407): Call is terminated
19:16:40.078 [CM503008]: Call(406): Call is terminated
19:16:40.078 [CM503008]: Call(406): Call is terminated
19:10:16.718 [CM503007]: Call(407): Device joined: sip:[email protected]:5060
19:10:16.703 [CM503007]: Call(407): Device joined: sip:[email protected]:59172;rinstance=8a377aff3da3d8d5
First of all, I've block all outgoing international calls for now but can someone suggest me a simple solution to stop this? Perhaps turning off stun? Changing the port for stun? I had set it up for external extensions but our off site sales guy is gone and that feature is no longer needed. How can I easily stop this because I dont' want to bleed any more money for these SOBs.