Outbound Call Hack

Status
Not open for further replies.

New Star Networks

Trainee Partner
Basic Certified
Joined
May 3, 2022
Messages
4
Reaction score
1
Hi All,

Wondering if anyone has run into this issue before where outbound calls are being spammed to a destination of the hackers choice.

I am seeing alot of these in the activity log for the extensions, only way to stop it is to disable the extensions, can't figure out a way to prevent it, found the users IP but its still happening, calls are GMT+2

Not removing number in case anyone recognizes it, and IP is VPN ip as well in Russia


05/03/2022 5:47:24 PM - [CM503001]: Call(C:25965): Incoming call from Extn:4105 to <sip:0034902578114@OurFQDN:0>
05/03/2022 5:47:24 PM - L:25965.1[Extn:4105] NoSDP - false
05/03/2022 5:47:24 PM - Leg L:25965.1[Extn:4105] has external party ID {}
05/03/2022 5:47:24 PM - L:25965.1[Extn:4105] joined to MSCall([email protected]:5482)
05/03/2022 5:47:24 PM - L:25965.1[Extn:4105] request to join MSCall [email protected]:5482
05/03/2022 5:47:24 PM - L:25965.1[Extn:4105] created MSEP ([email protected]:5482) (unbound)
05/03/2022 5:47:24 PM - L:25965.1[Extn:4105]: device's outbound URI is used: 89.205.56.24
05/03/2022 5:47:22 PM - L:25964.1[Extn:4105]: destroying InvADS.ADS(21328668)
05/03/2022 5:47:22 PM - Stop call record for leg L:25964.1[Extn:4105]
05/03/2022 5:47:22 PM - Removing leg L:25964.1[Extn:4105]

05/03/2022 5:48:06 PM (4105)0031206261254Not Answered
05/03/2022 5:48:01 PM (4105)0034902578114Not Answered
05/03/2022 5:47:24 PM (4105)0034902578114Not Answered
05/03/2022 5:47:22 PM (4105)0034902578114Not Answered
05/03/2022 5:47:21 PM (4105)0034902578114Not Answered
05/03/2022 5:47:20 PM (4105)0034902578114Not Answered
05/03/2022 5:47:18 PM (4105)0034902578114Not Answered



If anyone has some info on how to stop it
 
Have you changed credentials on the extension (web client, phone/app, etc)?
https://www.3cx.com/blog/unified-communications/dont-be-that-guy-vol-1/

Edit: one can Regenerate the extension's credentials from the 3CX Management Console, check the extension, and click the Regenerate button.

One can also block the IP in Security/IP Blacklist but that might be a waste of time if the IP changes frequently.
 
  • Like
Reactions: New Star Networks
Have you changed credentials on the extension (web client, phone/app, etc)?
https://www.3cx.com/blog/unified-communications/dont-be-that-guy-vol-1/

Edit: one can Regenerate the extension's credentials from the 3CX Management Console, check the extension, and click the Regenerate button.

One can also block the IP in Security/IP Blacklist but that might be a waste of time if the IP changes frequently.

Hi Steve,

Yes we have done this as well, we have blocked all ip's being used as VPN and also Firewall check is fine and everythgin is in place security wise.

It looks like external call is being made to the number and then the extension is replying yes it would like to join call then phones the number, so looks like some form of Calling attack as opposed to a System being compromised.
 
A small update on the situation for anyone else reading this, @New Star Networks has noticed that the issue stopped occurring after regenerating extension credentials so everything seems to be under control for now.
 
  • Like
Reactions: New Star Networks
Most likely that someone's email was compromised and they had the provsioning file/QR code. No matter how many times you change the password they can still get in. Regenerating the extension is the only way to invalidate that.
 
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,079
Members
164,896
Latest member
sameage