Just some fundamentals of how attackers operate and why the Global Blacklist works.
To orchestrate an attack, all they need is a net of machines they control to scan public IPs indiscriminately (anything from compromised webservers to user pcs). They can scan well known ports, and common variants by sending invites to them. If they send 1-2 invites and get a response you might not even realize it but, they know now that a SIP machine is sitting behind that ip and at that port.
Once they compile a list of IPs that are alive, they start hacking with brute force and other "tricks" in the hopes that they will get a valid sip account. That's when your PBX blacklists them, and shares the IPs with the 3CX Anti Hacking Defense Program. With so many compromised machines, many of which are on dynamic public IPs that keep changing, the attackers can quickly avoid being banned permanently.
The Global Blacklist will defend you by not replying to the known bad IPs, but since these change constantly, and newer, larger attack campaigns are launched from time to time (especially now that people are sitting at home and have more "free time") it is just a fact of life that sooner or later you will see your PBX blacklisting attackers. This is sign that it does what it should do and block them.
This addresses ALL the above questions you had, it's never personal, it's just generic attacks by opportunistic hackers that want to steal accounts to use them or sell them.
1) why specifically 3CX? - it's not specifically 3CX, its any SIP system that is online
2) why now? - guess what, hackers are locked indoors now and have more time to attack
3) will these IPs get blocked? - they will if you enabled global blacklist, just give it some time
4) will they get blocked if they re-offend? - yes they will but they can change IP easily and attack again
5) why User-Agent: 3CXPhoneSystem? - because its a known user agent just like Asterisk, Cisco etc
6) why only 2 or 3 of my systems getting attacked? - because those were discovered. the other will also be attacked eventually when someone scans them
I hope the above has covered a lot of ground on this subject.If you want more answers, you will have to ask the attackers themselves
