techniques to evade 3CX blacklist

Status
Not open for further replies.

Jose Lara

Gold Partner
Advanced Certified
Joined
Nov 1, 2007
Messages
285
Reaction score
7
The maximum number of attempts allowed by this PBX is 2, the attacker is waiting 10 minutes between each attempt and thus avoids being blacklisted.
It is certain that cybercriminals are learning how the system works and are implementing evasion techniques to try to gain access`.
1680556824917.png
 
There were other threads earlier this year I believe it was…the count/setting in the console is for SIP not the management console. Per 3CX the management console is supposed to be fixed at 10 failures. Obviously still not enough to block that IP.
 
The maximum number of attempts allowed by this PBX is 2, the attacker is waiting 10 minutes between each attempt and thus avoids being blacklisted.
It is certain that cybercriminals are learning how the system works and are implementing evasion techniques to try to gain access`.
View attachment 34999
Does this surprise you? The entirety of security, be it physical or cybersecurity is about moves and countermoves. This was happening long before 3CX and is nothing new. 3CX won't acknowledge or disclose how their blacklist works but I imagine they get that information as well and factor it in. You can always manually block it yourself or lookup the abuse contact for that ISP/netblock and reach out to them if so inclined. Also, this really isn't related to the supply chain attack so lets keep this section clean for so information pertaining to it does not get lost in the clutter.
 
  • Like
Reactions: ThomasD_3CX
There is a significant difference to older attacks seen at my aws servers.

Most login attemps were random endpoint numbers and passwords.

Joses logs shown are logins to the admin console. The Passwords looking like a list of more or less valid passwords. (Maybe someone should tell intercel.eu and proztec qatar they have been pwned and they likely should review their compliance policies on password strength)

My Logs often shows logins agains sip with bruteforced passwords.

Havent seen a log like Joses before. Anyone else did?

A very normal logfile while hosting @ AWS

Bildschirmfoto 2023-04-04 um 01.44.08.png
 
Last edited:
Hello guys this file appeared yesterday what is it?
looks like a strange shortcut that leads too 3cx should i be worried?
 

Attachments

  • first.jpg
    first.jpg
    49.9 KB · Views: 24
  • second.jpg
    second.jpg
    34.7 KB · Views: 23
This is not related to the supply chain attack and i already moved the threat
 
This is not related to the supply chain attack and i already moved the threat
Thanks for the fast reply so its a normal file made from 3cx? Sorry im a noob
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet