Shame all these cloud hosting providers don't have a firewall system that allows utilising constantly updated country lists that contain the IP blocks for a particular country. i.e. Only allow traffic from Australian IP's, resulting in 99% of attacks removed and remote users / users on mobile phone data connections to still connect.
Country based IP Blocks can help, and also hurt, ISPs are known to trade these blocks around, sometimes between countries as needed, usually not very rapidly, but still you can end up with blocks registered in one country, while actually being in another. So this isnt as bulletproof as it sounds.
Restricting your PBX to only Australian IPs for example would actually cause your PBX to cease to operate also, because it has to talk to 3CX's licensing servers, webmeeting servers, update servers, stun servers, lets encrypt servers to be able to update certificates, the Debian updates repository servers, the android and apple push servers.
Then you also prevent your people from working abroad, or going on business trips abroad with their 3CX Extensions on their mobile phones due to only allowing those IPs.
Please folks just stop. 3CX knows what they are doing and they provided an excellent explanation. This is not 3CX specific. This is how script kiddies work. The fact that you see 3CX as the UA just means that 3CX has become popular enough for hackers to include them in their kits. That's actually a good thing from the perspective as 3CX being recognized as a player in the VoIP market.
@cobaltit is right on point here! The useragent part is forged by hackers for three reasons:
1. So that their hit on the blocklist appears harmless to a Sysadmin, and they ignore it.
2 So that their hit on the blocklist appears harmless to a Sysadmin, and a gullible sysadmin white-list's it and mistakes it as a user having problems.
3. To get past any useragent specific blocking done by Firewalls and WAF systems.
They are trying to fool dummies, nothing more.
As to why you see it hit some instances and not others it's really simple. They tell there script to scan certain IP blocks and they let it run and generally IP blocks belong to a single provider/ISP. As long as you stick with 3CX defaults (complex extension passwords, extensions not accessible from the outside) and you turn on the global blacklist you are fine. You aren't special enough to be specifically targeted. At best these script kiddies are looking to perform toll fraud which setting appropriate country restrictions and alerts will let you know well before it gets out of hand.
@cobaltit is absolutely on point here also, but i will add to it, Many scanning tools can also randomize the order of the IPs they scan these days, so that a Sysadmin does not see a scanner hitting each servers IP address in sequence and block it early in their scan attempt. They are trying to fly under the radar, but also scan as quickly as possible, that is how they try to accomplish both goals. So when you see IPs being skipped, that is why.
Setup 3CX's global blacklist as
@cobaltit says, and i agree, and you will not have any issues, 3CX has more protection in its code below the surface that you don't see without looking under the hood, just because you don't see it does not mean it isnt there, I have seen it btw. Make sure all your extensions and your admin password follow strict password policies, at least equal to those 3CX uses within, if your really worried, make them longer manually.
99.99995% of the time those scans are automated, unless you have made an enemy, noone is actually at the keyboard attacking your 3CX Server, there are far easier methods to trick somebody into letting them in, usually with E-Mails.
And do make sure your system is set with country restrictions reasonably, as stated by
@cobaltit The main goal is monetary, they get an extension online, and commit toll fraud.
An alternate i have seen before, though never successfully exploited on 3CX, was a hacker got an extension online to an Avaya IP500 which is shi7-for-brains security wise, and they used it to call people claiming to be microsoft, and extort money claiming to be cleaning up viruses, im sure you have heard of them, they use other peoples PBXs they hack into so the calls are untraceable. I was brought in to investigate strange operations on their network, and discovered they were using the IP500 not only to make fraud calls, but they had breached it enough to pivot into the servers of that facility as well, and were using them to launch paid flood attacks from the servers.
If you are really worried about security, you need to work with someone with a security background like
@BrenttG . This isn't 3CX specific.
Im always happy to collect people's money to secure things, you would be surprised how often though that the best practices and common sense approaches are all I have to do to strengthen things significantly because someone else overlooked them, didn't care, or thought they new better falsely.