- Joined
- Apr 19, 2022
- Messages
- 18
- Reaction score
- 1
Hello experts,
today was one of those "Oh boy" days.
This morning around 8:40am i started receiving Alerts from my system about the trunk limits. Continuously and they would not stop. However there's more to that. One of my user or the whole department started receiving calls via one of the trunks about posted shipments from one of my user's account. Users themselves did not post anything and they did not know what is going on. Well one of the user's brokerage account has been compromised reaching hundreds of posts on the board. What's interesting is the shipments posts included our sip trunk number with my user's extension. At the same time my 3cx system started receiving all these alerts about trunk limits every minute. When i opened the Active Calls window and call logs i saw there tens or hundreds of calls from random numbers made to our sip trunk. In order to mitigate this attack and somehow release the load so that my other sip trunks can make calls, i immediately disabled the attacked sip trunk, unchecked Inbound and Outbound calls under sip trunk Options and disabled the actual sip Trunk from Telnyx dashboard itself. Yes, this trunk was originally bought from Telnyx. We immediately reset User's email, passwords, extension passwords.
The system immediately started working and back to normal again however here's the interesting part:
Right now its almost 3pm and the alerts are still coming about maximum calls on the trunk, every minute. My inbox is full of them. What i receive in the email is this as an example:
Device 4072057923@(Ln.10003@DL) had no available outgoing trunk(s) to call(31784)
Device 6305800777@(Ln.10003@DL) had no available outgoing trunk(s) to call(31847)
Device 2165700978@(Ln.10003@DL) had no available outgoing trunk(s) to call(31848)
A trunk failover occurs when the maximum amount of calls available via the trunk have been exceeded.
These device numbers are random. This is where i need your help. My question is: Does this look like my system is compromised? Is there an infected internal device that is still trying to make calls via this trunk? What can i do to stop this? I removed one of the generic operator extensions that was in this department as a precaution and looks like right around that time the alerts have stopped. I unplugged some of the desk phones for now from that department. Only 4 people in that department. What's throwing me off is that
no other notifications from other trunks are coming, and the system is working as normal meaning my users can make and receive calls, otherwise the whole system would have gone rogue.
today was one of those "Oh boy" days.
This morning around 8:40am i started receiving Alerts from my system about the trunk limits. Continuously and they would not stop. However there's more to that. One of my user or the whole department started receiving calls via one of the trunks about posted shipments from one of my user's account. Users themselves did not post anything and they did not know what is going on. Well one of the user's brokerage account has been compromised reaching hundreds of posts on the board. What's interesting is the shipments posts included our sip trunk number with my user's extension. At the same time my 3cx system started receiving all these alerts about trunk limits every minute. When i opened the Active Calls window and call logs i saw there tens or hundreds of calls from random numbers made to our sip trunk. In order to mitigate this attack and somehow release the load so that my other sip trunks can make calls, i immediately disabled the attacked sip trunk, unchecked Inbound and Outbound calls under sip trunk Options and disabled the actual sip Trunk from Telnyx dashboard itself. Yes, this trunk was originally bought from Telnyx. We immediately reset User's email, passwords, extension passwords.
The system immediately started working and back to normal again however here's the interesting part:
Right now its almost 3pm and the alerts are still coming about maximum calls on the trunk, every minute. My inbox is full of them. What i receive in the email is this as an example:
Device 4072057923@(Ln.10003@DL) had no available outgoing trunk(s) to call(31784)
Device 6305800777@(Ln.10003@DL) had no available outgoing trunk(s) to call(31847)
Device 2165700978@(Ln.10003@DL) had no available outgoing trunk(s) to call(31848)
A trunk failover occurs when the maximum amount of calls available via the trunk have been exceeded.
These device numbers are random. This is where i need your help. My question is: Does this look like my system is compromised? Is there an infected internal device that is still trying to make calls via this trunk? What can i do to stop this? I removed one of the generic operator extensions that was in this department as a precaution and looks like right around that time the alerts have stopped. I unplugged some of the desk phones for now from that department. Only 4 people in that department. What's throwing me off is that
no other notifications from other trunks are coming, and the system is working as normal meaning my users can make and receive calls, otherwise the whole system would have gone rogue.