Our asterisk server was compromised. some calls were made to Asia countries last weekend.
Thought we have improved our network configuration, we still want to determine how the intrusion was done, we think there are clues in our asterisk log files.
but we don't know what to look for, based in a default asterisk: