Thursday, February 27, 2025
HomeMalware52,000 Dangerous Command & Control Servers Take Down that Spreading Malware: It...

52,000 Dangerous Command & Control Servers Take Down that Spreading Malware: It Performs 2M Malicious Redirects a Day

Published on

SIEM as a Service

Follow Us on Google News

Around 52,000 Malicious Command & Control Severs has been taken down that continuously spreading Malware under well-documented infection chain called EITest.

EITest is a Sophisticated Malware infection chain that basically redirects users from a compromised website into exploit kit (EK) landing pages, social engineering schemes, and potential threats.

Its one of the oldest & largest infection chains, that performed a variety of dangerous infection by distributing ransomware, information stealers, and other malware.

Recent Years EITest is one of the main sellers of malicious traffic to Exploit Kit (EK) operators and social engineering operations via compromised websites.

Also Read: Cloudflare Launches Spectrum to Protect Almost Entire Internet

EITest Infection History with Exploit Kit

Initially, during the period of 2017 researchers identified that it started using a variety of social engineering tactics and it was redirecting to a private EK known as Glazunov during 2013 and also its stared infecting rework infrastructure in the same year.

Later it directed into Angler Exploit Kit(EK) and the threat actors main motivation to spreading Zaccess Trojan and Glazunov was a private Exploit Kit(EK) used only by the EITest operators.

its reemerged again in 2014 with new infection pattern and started infecting with a new payload with 2 different categories

  • The actor is selling loads (infections) or
  • The actor is selling traffic (to other actors, a load seller, or both)
Accorinding to the Research that conducted by Proofpoint along with brillantit.com and abuse.ch, Based on EITest actor activity on underground forums and insights from Empire Exploit Kit(EK)  we confirmed that the actor was selling traffic. In 2014, we found that the actor was selling traffic in blocks of 50-70,000 visitors for US$20 per thousand, generating between $1,000 and $1,400 per block of traffic.

Recent Main infection chain via EITest mainly for social engineering, tech support scams that lead to eventually infected by the ransomware.

Malicious Servers take down by Sinkholing operation

Researchers create a new domain and Sinkholing (redirection of traffic from its original destination) the EITest operation that has been pointed to a new  IP address.

By generating those new domains, researchers were able to substitute the malicious server with a sinkhole in order to receive the traffic from the backdoors on the compromised websites.

Later they freeing them from the EITest C&Cs and their visitors from the resulting malicious traffic and injects.

The red box highlights the server we substituted with a sinkhole

Researchers analyzing the traffic using this Sinkholing operation and observe that sinkhole received almost 44 million requests from roughly 52,000 servers between  March 15 to April 4, 2018.

Aslo they decoding the malicious request and find the list of compromised domains as well as IP addresses and user agents of the users who had browsed to the compromised servers.

Those compromised websites are multiple content management systems and WordPress websites are the most infected websites.

Indicators of Compromise (IOCs)

IOCIOC TypeDescription
54dfa1cb[.]com|31.184.192.163domain|ipEITest C&C (before sinkholing)
e5b57288[.]com|31.184.192.173domain|ipEITest C&C (before sinkholing)
33db9538[.]com|31.184.192.173domain|ipEITest C&C (before sinkholing)
9507c4e8[.]com|31.184.192.163domain|ipEITest C&C (before sinkholing)
04d92810[.]comdomainEITest Sinkhole
c84c8098[.]comdomainEITest Sinkhole
e42d078d[.]comdomainEITest Sinkhole
498296c9[.]comdomainEITest Sinkhole
stat-dns[.comdomainSeized domain controlling the DGA
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts

GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform...

LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows

A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has...

Cisco Nexus Switch Vulnerability Allows Attackers to Cause DoS

Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000...

Silver Fox APT Hackers Target Healthcare Services to Steal Sensitive Data

A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Ghostwriter Malware Targets Government Organizations with Weaponized XLS File

A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group...

LCRYX Ransomware Attacks Windows Machines by Blocking Registry Editor and Task Manager

The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its...

Threat Actors Using Ephemeral Port 60102 for Covert Malware Communications

Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade...