On March 15, 2018, Proofpoint, abuse.ch, and researcher @Secu0133 redirected EITest’s command-and-control traffic to a sinkhole by taking control of a domain used to generate its command domains. The operation disrupted the identified infrastructure; it did not, by itself, clean every compromised website. Proofpoint’s observations cover March 15 through April 4, 2018, and do not establish EITest’s status today.
What EITest did
EITest was an infection chain that used compromised websites to send visitors toward malicious destinations. Depending on the campaign, those destinations included exploit-kit landing pages, social-engineering schemes, and other payloads. Proofpoint assessed that EITest’s operators also sold redirected traffic to other threat actors.
Proofpoint’s April 12, 2018 account traces clear evidence of EITest-related activity to 2011, when the chain was associated with the private Glazunov exploit kit. The report describes a pause from late 2013 into 2014 and a return to observed activity in July 2014. EITest then directed traffic to Angler and later routed visitors toward multiple downstream payloads. A January 2017 Proofpoint report describes the chain’s changing redirect strategy and the researchers’ assessment that its operators sold traffic to other groups. Proofpoint’s 2017 analysis.
How the sinkhole operation worked
A sinkhole redirects traffic intended for malicious infrastructure to a server controlled by researchers or defenders. In this case, the researchers analyzed an EITest PHP script and identified stat-dns.com as a key domain used to generate command-and-control (C&C) domains. On March 15, 2018, they took control of that domain, generated four new EITest C&C domains through it, and pointed those domains to an abuse.ch sinkhole. Proofpoint’s April 12, 2018 report.
Recommended Free Tools
#1 Best Overall
- Identify the domain-generation mechanism: Researchers examined the EITest PHP script and found the domain involved in generating C&C domains.
- Take control of the key domain: The collaborators gained control of stat-dns.com.
- Redirect the generated C&C domains: They generated four new EITest C&C domains and directed them to the abuse.ch sinkhole.
- Observe and disrupt the redirected traffic: Backdoor communications from compromised sites reached the sinkhole rather than the identified malicious server.
This interrupted the observed connection to EITest’s C&C infrastructure. It was not equivalent to removing malicious code from every affected website: a sinkhole redirects communications, while site cleanup requires separately finding and removing the compromise.
What the researchers observed
From March 15 through April 4, 2018, Proofpoint recorded nearly 44 million requests from roughly 52,000 servers at the sinkhole. These are observed requests and servers, not confirmed unique victims or infected people. Most of the compromised sites appeared to run WordPress, although Proofpoint also observed sites using other content-management systems. The report’s measurement summary.
Proofpoint estimated that the operation prevented as many as two million potential malicious redirects per day. That figure is the researchers’ estimate of potential impact, not a measured tally of users protected or infections prevented.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What happened to the observed infrastructure—and what remains unknown
Proofpoint reported that the actor shut down the observed C&C proxies after the sinkhole operation and that the researchers shared information about compromised sites with national CERTs. The report also describes encoded calls arriving at the sinkhole that appeared to contain commands associated with attempts to take control of sites. The researchers could not verify whether those requests came from EITest’s operators, other researchers, or other threat actors. The report therefore does not establish that an operator takeover succeeded or determine the eventual status of every compromised site. Proofpoint’s conclusion and caveats.
Proofpoint’s report was published April 12, 2018. Its findings describe the infrastructure and traffic observed during the 2018 operation; they do not show whether EITest later reappeared or establish its present-day status.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

