It isn't always defaults: Scans for 3CX usernames

    Published: 2025-11-10. Last Updated: 2025-11-10 15:23:31 UTC
    by Johannes Ullrich (Version: 1)
    2 comment(s)

    Today, I noticed scans using the username "FTP_3cx" showing up in our logs. 3CX is a well-known maker of business phone system software [1]. My first guess was that this was a default user for one of their systems. But Google came up empty for this particular string. The 3CX software does not appear to run an FTP server, but it offers a feature to back up configurations to an FTP server [2]. The example user used in the documentation is "3cxftpuser", not "FTP_3cx". Additionally, the documentation notes that the FTP server can run on a different system from the 3CX software. For a backup, it would not make much sense to have it all run on the same system.

    The scans we are seeing likely target FTP servers users set up to back up 3CX configurations, and not the 3CX software itself. I am not familiar enough with 3CX to know precisely what the backup contains, but it most likely includes sufficient information to breach the 3CX installation.

    The credentials we observe with our Cowrie-based honeypots are collected for telnet and ftp. In particular, on Linux systems, you often use a system user to connect via FTP. Any credentials working via FTP will also work for telnet or SSH. Keep that in mind when configuring a user for FTP access, and of course, FTP should not be your first choice for backing up sensitive data, but we all know it does happen.

    Here are the passwords attacks are attempting to use:

    Password Count
    3CXBackup 4
    3CXbackups 4
    telecom 1
    testbackup 1
    backup3cx 1
    ebsftpuser 1
    ftp_cxn 1
    ftp_inx 1

    Here are some other "3cx" related usernames we have seen in the past:

    Username
    3cx
    3CXBackup
    3cxbackups
    backup3cx
    ftp3cx
    FTP_3cx

    If anyone with more 3CX experience reads this, is there a reason for someone to use these usernames? Or are there any defaults I didn't find?

    [1] https://www.3cx.com
    [2] https://www.3cx.com/docs/ftp-server-pbx-backups-linux/

    --
    Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
    Twitter|

    Keywords: 3cx
    2 comment(s)
    ISC Stormcast For Monday, November 10th, 2025 https://isc.sans.edu/podcastdetail/9692

      Comments


      Diary Archives