Relentless SPAM Calls

lightspeedhosting

Bronze Partner
Basic Certified
Joined
Nov 26, 2019
Messages
27
Reaction score
2
I have quite a few installations but I only have 1 multi-tenant installation and 1 particular DID on that system gets hundreds and hundreds of SPAM calls ago from the same SPAMMER...

I thought at first, I will solve this through Twilio at the SIP trunk level but to my surprise Twilio is showing ZERO incoming calls on that DID. So I looked at the 3CX Call logs and I can see calls being placed to that number from: <locally random masked number>@:0

Because of this, it appears that this spammer is actually contacting my DID directly thru 3CX.

1) Shouldn't there be a way to drop these calls? Any legitimate call would have a valid SIP origination????
2) Because I am using FQDN service, shouldn't I be able to setup so that no calls go thru unless they go through the FQDN thus allowing me to at least block the direct IP access?

EDIT: for the time being, I setup an IVR that the number in question goes to. It requests that the caller press 1 to verify they're not a bot (all the calls are computer with a pre-recording), and if they press 1 then it forwards it to my extension. This doesn't so much solve the problem as it does bandaid it for now. Would love a solution.
 
Last edited:
If you do not expect direct SIP calls then you can firewall the PBX and only allow your Trunk provider and local networks to reach the SIP ports.

That would be the most secure and definitive way. You might also do a packet capture and see what IP(s) those calls are coming from and simply blacklist those in the PBX directly.
 
Hello lightspeedhosting,
Do you by any chance have another SIP trunk which is IP Based on the same system or have the Direct SIP call option enabled in System / Options / Allow Direct SIP calling ?
As having those could explain why these inbound calls are being allowed in. Further filtering on firewall level or additional source identification settings may be needed to tighten the configuration.

The easiest to stop this for now would be to add the source IP to your blacklist. You can identify it using the Activity Logs and searching for one of the <locally random masked number>. Then look around the SIP INVITE packet, the source IP is typically found on the first line in label "INVITE from xxx" or in the SIP field "Via: ... received=xxx".
If there are no findings you will need to raise the Logging Level until it reoccurs.
 
Hello lightspeedhosting,
Do you by any chance have another SIP trunk which is IP Based on the same system or have the Direct SIP call option enabled in System / Options / Allow Direct SIP calling ?
As having those could explain why these inbound calls are being allowed in. Further filtering on firewall level or additional source identification settings may be needed to tighten the configuration.

The easiest to stop this for now would be to add the source IP to your blacklist. You can identify it using the Activity Logs and searching for one of the <locally random masked number>. Then look around the SIP INVITE packet, the source IP is typically found on the first line in label "INVITE from xxx" or in the SIP field "Via: ... received=xxx".
If there are no findings you will need to raise the Logging Level until it reoccurs.

I do not have direct SIP calling enabled. I've been digging into packet traces and such and it appears that the calls ARE IN FACT coming through Twilio.

When I go to the number's log, it does NOT show the call incoming, but if I go to Twilio's "all calls log" those calls show up coming into that number.

What I did at least in the meantime, was to setup an IVR that asks the caller to Press 1 to verify they're not a bot, and then if they do it forwards the call to my extension. So now the IVR answers the calls instead of being pass thru. This works like a charge, and I guess in the meantime I can figure out with Twilio how to tracking down these prolific scam call operations
 

Forum statistics

Threads
111,954
Messages
589,919
Members
164,851
Latest member
DrunkeMeister