TL;DR: Full investigation below, but the spam-calling nuisance that's been annoying everyone for the last couple of weeks is probably yet another failed piece of "AI" slopware. I would love to know what the actual idea was here.
An entity on the network with identity hash d14f05add53c03486d6f869cda37afbf has been spam-calling every LXST telephony destination since the beginning of May. The behavior seems perfectly weird.
If this is intentionally malicious, the frequency and operation mode is very strange. From initial observations, it is doing the following:
- When an
lxst.telephonydestination announces on the network, it will establish a link to this destination. - It then sends an on-link identification, identifying itself as
d14f05add53c03486d6f869cda37afbf. - Keeps the link open, but does nothing else.
This results in the receiving lxst.telephony destination ringing, but on picking up the call, nothing happens. To make things even weirder, consider the following:
The spam-calling d14f05add53c03486d6f869cda37afbf identity has never announced an lxst.telephony destination on the network, but it does announce an lxmf.delivery destination every 5 minutes.
> rnid -i d14f05add53c03486d6f869cda37afbf -H lxst.telephony
Recalled Identity <d14f05add53c03486d6f869cda37afbf>
The lxst.telephony destination for this Identity is <184c754ddaf5750a653a605fc97fd2ea>
The full destination specifier is <lxst.telephony.d14f05add53c03486d6f869cda37afbf:184c754ddaf5750a653a605fc97fd2ea>
❯ rnpath 184c754ddaf5750a653a605fc97fd2ea
Path not found
❯ rnid -i d14f05add53c03486d6f869cda37afbf -H lxmf.delivery
Recalled Identity <d14f05add53c03486d6f869cda37afbf>
The lxmf.delivery destination for this Identity is <5954a9633c043df82b207e1a5dc3998a>
The full destination specifier is <lxmf.delivery.d14f05add53c03486d6f869cda37afbf:5954a9633c043df82b207e1a5dc3998a>
❯ rnpath 5954a9633c043df82b207e1a5dc3998a
Path found, destination <5954a9633c043df82b207e1a5dc3998a> is 5 hops away via <a5d6fc0d5669f4151ff944fca58aeafc> on AutoInterfacePeer[x/x]