- Joined
- Oct 18, 2016
- Messages
- 10
- Reaction score
- 1
Dear Forum
This day our system log full with unknown call to unknown destination.
It seem someone already registered with fake user and make that call.
This are output from the call log.
===================================================
01/09/2017 8:48:13 AM (@(Ln.20000@JAKARTA HQ)) 0101722063047451 Not Answered
01/09/2017 8:48:08 AM (@(Ln.20000@JAKARTA HQ)) 9007972592317313 Not Answered
01/09/2017 8:47:08 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:47:04 AM (@(Ln.20000@JAKARTA HQ)) 007972599979917 Not Answered
01/09/2017 8:46:53 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:46:43 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:46:39 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:44:00 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:01:22
01/09/2017 8:41:28 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:03:57
01/09/2017 8:35:37 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:09:43
01/09/2017 8:28:36 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:12:06
01/09/2017 8:27:54 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:15:25
01/09/2017 8:27:54 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:17:24
01/09/2017 8:26:01 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:09:29
01/09/2017 8:25:51 AM (@(Ln.20000@JAKARTA HQ)) 010170101722063733292 Not Answered
=========================================================================
And this is are some suspicious log from event log
==========================================================================
SIP Server/Call Manager ID: 4101
Extension 32202 is unregistered, removed contact: sip:[email protected]:50195;transport=TCP;rinstance=1-9r88maescugl8lxcr7ras5y29d6y0brk;ob;inst="3f55ae51"
SIP Server/Call Manager ID: 4101
Extension 32202 is registered, contact: sip:[email protected]:50195;transport=TCP;rinstance=1-9r88maescugl8lxcr7ras5y29d6y0brk;ob;inst="3f55ae51"
=======================================================================
In order to mitigate this, i block outbound call from Ln.20000@JAKARTA HQ and blacklisted some suspicious IP address
Can someone help us to hardening this system ?
regards
Reza
This day our system log full with unknown call to unknown destination.
It seem someone already registered with fake user and make that call.
This are output from the call log.
===================================================
01/09/2017 8:48:13 AM (@(Ln.20000@JAKARTA HQ)) 0101722063047451 Not Answered
01/09/2017 8:48:08 AM (@(Ln.20000@JAKARTA HQ)) 9007972592317313 Not Answered
01/09/2017 8:47:08 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:47:04 AM (@(Ln.20000@JAKARTA HQ)) 007972599979917 Not Answered
01/09/2017 8:46:53 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:46:43 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:46:39 AM (@(Ln.20000@JAKARTA HQ)) 0101722063733292 Not Answered
01/09/2017 8:44:00 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:01:22
01/09/2017 8:41:28 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:03:57
01/09/2017 8:35:37 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:09:43
01/09/2017 8:28:36 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:12:06
01/09/2017 8:27:54 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:15:25
01/09/2017 8:27:54 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:17:24
01/09/2017 8:26:01 AM (@(Ln.20000@JAKARTA HQ)) 90101722063733292 00:09:29
01/09/2017 8:25:51 AM (@(Ln.20000@JAKARTA HQ)) 010170101722063733292 Not Answered
=========================================================================
And this is are some suspicious log from event log
==========================================================================
SIP Server/Call Manager ID: 4101
Extension 32202 is unregistered, removed contact: sip:[email protected]:50195;transport=TCP;rinstance=1-9r88maescugl8lxcr7ras5y29d6y0brk;ob;inst="3f55ae51"
SIP Server/Call Manager ID: 4101
Extension 32202 is registered, contact: sip:[email protected]:50195;transport=TCP;rinstance=1-9r88maescugl8lxcr7ras5y29d6y0brk;ob;inst="3f55ae51"
=======================================================================
In order to mitigate this, i block outbound call from Ln.20000@JAKARTA HQ and blacklisted some suspicious IP address
Can someone help us to hardening this system ?
regards
Reza