TVSPY: Advanced Persistent Threat

The TVSPY APT seems to grow each year, the report from Damballa shows that in 2012 only 5 unique TVSPY samples were identified, in 2013, this number was raised to 8 and in 2014 the number was set on 10 unique malware samples.

And finally, in 2015, 22 unique samples were identified by Damballa. ESET and GROUP-IB have discussed this APT in 2011 as a “crimeware” attack, but Kaspersky mentioned the TVSPY attack as an APT in their 2013 report.

The TVSPY malware is being sold on underground forums for a value of 400 dollars and according to the report, the developer behind TVSPY would be someone which uses the “Mr.Burns” handle. The person which is currently selling the TVSPY malware on underground forums uses the handle “Scalpel”.

Searching with Google Dorks

The following Google Dork should allow you to search Spy Agent / TVSPY C&C environments: 

intext:SpY-Agent. Логин: Пароль: SpY-Agent

Scalpel is also identified by the following nicknames:

  • scalpel
  • brutalisk
  • overd0s3r

The following MD5 values can be used to find malicious TVSPY payloads:

  • a55149b4164659d5c0e1cd2daef9a702
  • 21670682a47021cc4be53ea832df7dbd
  • efa5c157946125734184a1cb62c6a0e1
  • f84928ea5b4752b9cc2a7ae2155d6fd5
  • 688be0a5684dbe633ea86d3640e33d47
  • 070859ed01990f003b78d9820e77d72e
  • 9146902c590c98b8b2c4bb7d323623cd
  • c3de5426a4fec6e97acd1f693081615e
  • 8852fb707e1a5c5d505b6a026e8ddab5
  • 718633f40da55c76f0c6c7c81824799f
  • b36a11b189242e071e8c8e564aab56e2
  • 2afa10d90a4899f9215f77b1db9230e3
  • 99bdcab182678da0dcf52aa4a0795b05
  • d88e492a0c91441bc4385e0dfe69caf2
  • 09e20b095e0aa1d8aa2f9c16ff76b1e9
  • 407cd02af6ea3a7b2d4246ba8f89b076
  • 71d1cf7dc21dfa5fa0a615cfa06dc297
  • 255e3db5aa603384d2ca4594b18dc609
  • fd90061743e0f33ae5135cb2fbf7057e
  • 0c368c121f13928d9699fbc93eead367
  • 4414e69f4b895551f5a90abb59ff2330
  • 30ebfdc2a2e90ccd0649ccdf853f1e9d
  • bc8eb8677390f90de921592c86f17040
  • 3a8455584bda5951b8c0a05deed87b4f
  • eb88459f2d532fa3fcc081e2e6a1d549
  • 008cc983f88b87f8b804988ac4c8d532
  • 7a5972a7038f224ff97e02c13082e418
  • 33d079af33b3689a9d6a9517b39c8d7b
  • 5190aa75867dde7ca172c2c30d19dcf3
  • 4a9fdd47041252608801d16b4ac11e12
  • b4dc51648fa10c349453d80c8cfabed2
  • 13467f0886de6d0c6716ac0a4eeb2f59
  • c5c05c0f4b9e3b6ac2ad51dc15ef8f43
  • f7a4602db94cd67e9c03d918eaef91a2
  • 8b0d8f1d06aea9bc5c7477c9c8284713
  • 4c177ad2a07a304318d09fc4ef389a09
  • 1a141a76d12f7a310ade141133c0a37c
  • a5aff9aa5b2e45a0f9fea080f8f15971
  • 1a9b23d9e18c5d19e86fc5a89012a0ef
  • 8230f1f93245528c1faa82d945c25332
  • 18faa7856fda324ed06261368ab72829
  • b7ab83f84103130e46e95de0df8d85a4
  • 740d9cd8ea165302aa3cd7e6f198ea4c
  • 9079fc3edc31956ab63bbb23673e6c7c
  • 1fe21a120f524bb914b210284e1caf05
  • 36f2049cc1a5db224fcd6541d630677f
  • 58f1852af6a270d385f270d60d00a0a5

TVSPY Host and hashes:

util4u.com 070859ed01990f003b78d9820e77d72e
aflnatour.ru 9146902c590c98b8b2c4bb7d323623cd
aflnatour.ruadmin 9146902c590c98b8b2c4bb7d323623cd
tim-t.ru c3de5426a4fec6e97acd1f693081615e
aflnatour.ru 8852fb707e1a5c5d505b6a026e8ddab5
aflnatour.ruadmin 8852fb707e1a5c5d505b6a026e8ddab5
ac.myjino.ru 718633f40da55c76f0c6c7c81824799f
util4u.com b36a11b189242e071e8c8e564aab56e2
mmm-svoboda2012.ru 2afa10d90a4899f9215f77b1db9230e3
tim-t.ru 99bdcab182678da0dcf52aa4a0795b05
mmm-svoboda2012.ru d88e492a0c91441bc4385e0dfe69caf2
darlingday.ru 09e20b095e0aa1d8aa2f9c16ff76b1e9
util4u.com 407cd02af6ea3a7b2d4246ba8f89b076
mmm-svoboda2012.ru 71d1cf7dc21dfa5fa0a615cfa06dc297
statisticsystic.com 255e3db5aa603384d2ca4594b18dc609
f1rst.name fd90061743e0f33ae5135cb2fbf7057e
tvincoming.com 0c368c121f13928d9699fbc93eead367
f1rst.name 4414e69f4b895551f5a90abb59ff2330
filidaro.com 30ebfdc2a2e90ccd0649ccdf853f1e9d
util4u.com bc8eb8677390f90de921592c86f17040
util4u.com 3a8455584bda5951b8c0a05deed87b4f
f1rst.name eb88459f2d532fa3fcc081e2e6a1d549
filidaro.com 008cc983f88b87f8b804988ac4c8d532
mmm-svoboda2012.ru 7a5972a7038f224ff97e02c13082e418
f1rst.name 33d079af33b3689a9d6a9517b39c8d7b
doomns.mooo.com 5190aa75867dde7ca172c2c30d19dcf3
bestkassa.com 4a9fdd47041252608801d16b4ac11e12
162.211.230.170 b4dc51648fa10c349453d80c8cfabed2
nynewsguardianinternet.com 13467f0886de6d0c6716ac0a4eeb2f59
bestkassa.com c5c05c0f4b9e3b6ac2ad51dc15ef8f43
109.234.35.77 f7a4602db94cd67e9c03d918eaef91a2
78.47.135.84 8b0d8f1d06aea9bc5c7477c9c8284713
5.45.70.137 4c177ad2a07a304318d09fc4ef389a09
194.63.142.171 1a141a76d12f7a310ade141133c0a37c
78.47.135.84 a5aff9aa5b2e45a0f9fea080f8f15971
cdn-rskp.com 1a9b23d9e18c5d19e86fc5a89012a0ef
blackvfl.com 8230f1f93245528c1faa82d945c25332
91.215.155.46 18faa7856fda324ed06261368ab72829
206.su b7ab83f84103130e46e95de0df8d85a4
206.su 740d9cd8ea165302aa3cd7e6f198ea4c
92.53.96.101 21670682a47021cc4be53ea832df7dbd
91.215.155.46 9079fc3edc31956ab63bbb23673e6c7c
bestkassa.com 1fe21a120f524bb914b210284e1caf05
91.215.155.48 f84928ea5b4752b9cc2a7ae2155d6fd5
178.63.249.40 36f2049cc1a5db224fcd6541d630677f
blackvfl.com 58f1852af6a270d385f270d60d00a0a5
canterus.com a55149b4164659d5c0e1cd2daef9a702