# Boost Beast check in and response

**URL:** <https://community.emergingthreats.net/t/boost-beast-check-in-and-response/288>\
**Category:** Rule Signatures\
**Created:** [January 28, 2023, 3:20pm UTC](https://community.emergingthreats.net/t/boost-beast-check-in-and-response/288 "2023-01-28T15:20:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![NoahWolf](https://avatars.discourse-cdn.com/v4/letter/n/a6a055/32.png) [@NoahWolf](https://community.emergingthreats.net/u/NoahWolf)\
**Post date:** [January 28, 2023, 3:20pm UTC](https://community.emergingthreats.net/t/boost-beast-check-in-and-response/288/1 "2023-01-28T15:20:15Z")

</div>

Found this Pcap, not really sure if it is malware or not.

Here is my signature for the check in,

alert tcp $HOME\_NET any → $EXTERNAL\_NET any (msg:“boost beast check in”; http.uri; content:“/api/taskforecast/get”; http.method; content:“GET”; reference:url,[file (MD5: 73923A750344D1A1E734A12E98271C69) - Interactive analysis - ANY.RUN](https://app.any.run/tasks/556c8a11-a736-48db-9779-bb74db2431c6/); sid:2008005; rev:1;)

Here is my signature for the response,

alert tcp $EXTERNAL\_NET any → $HOME\_NET any (msg:“boost beast response”; content:“{"Id"”; content:“Report”; content:“Watch”; content:“Action”; reference:url,[file (MD5: 73923A750344D1A1E734A12E98271C69) - Interactive analysis - ANY.RUN](https://app.any.run/tasks/556c8a11-a736-48db-9779-bb74db2431c6/); sid:2008006; rev:1;)

---

<div class="post-metadata">

**Author:** ![bmurphy](https://avatars.discourse-cdn.com/v4/letter/b/f19dbf/32.png) [@bmurphy](https://community.emergingthreats.net/u/bmurphy)\
**Post date:** [January 30, 2023, 9:57pm UTC](https://community.emergingthreats.net/t/boost-beast-check-in-and-response/288/2 "2023-01-30T21:57:22Z")

</div>

Thanks @NoahWolf - I’ll take a look at these tonight and see what I can find out.

At first glance this looks ADWARE\_PUP related.

Where did you get the naming “Boost Beast” from?

---

<div class="post-metadata">

**Author:** ![NoahWolf](https://avatars.discourse-cdn.com/v4/letter/n/a6a055/32.png) [@NoahWolf](https://community.emergingthreats.net/u/NoahWolf)\
**Post date:** [January 31, 2023, 1:24pm UTC](https://community.emergingthreats.net/t/boost-beast-check-in-and-response/288/3 "2023-01-31T13:24:24Z")

</div>

I got the name “Boost Beast” from the strings output of the binary.

It is from a library that the binary uses. Probably not best to name it after a library its using, but I could not find anything else in the binary that would lead to a name.

---

<div class="post-metadata">

**Author:** ![bmurphy](https://avatars.discourse-cdn.com/v4/letter/b/f19dbf/32.png) [@bmurphy](https://community.emergingthreats.net/u/bmurphy)\
**Post date:** [January 31, 2023, 6:42pm UTC](https://community.emergingthreats.net/t/boost-beast-check-in-and-response/288/4 "2023-01-31T18:42:39Z")

</div>

Ok, finally got around to taking a good look at this today.

I’ve detailed my analysis of the samples and have provided some feedback on your proposed rules! Today there will be five new rules released based on your research 🎉. ~~I’ll be sure to update the post with the sids and rule content once they are released~~.

SIDs

```auto
  2044038 - ET ADWARE_PUP BoostBeast Task Request M1 (adware_pup.rules)
  2044039 - ET ADWARE_PUP BoostBeast Task Request M2 (adware_pup.rules)
  2044040 - ET ADWARE_PUP BoostBeast Checkin M1 (adware_pup.rules)
  2044041 - ET ADWARE_PUP BoostBeast Checkin M2 (adware_pup.rules)
  2044042 - ET ADWARE_PUP BoostBeast Task Response (adware_pup.rules)

```

Rules

```auto
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP BoostBeast Task Request M1"; flow:established,to_server; http.method; content:"GET"; http.uri; bsize:21; content:"/api/taskforecast/get"; fast_pattern; threshold:type limit, count 1, seconds 120, track by_src; reference:url,app.any.run/tasks/556c8a11-a736-48db-9779-bb74db2431c6/; reference:md5,73923a750344d1a1e734a12e98271c69; classtype:pup-activity; sid:2044038; rev:1; metadata:attack_target Client_Endpoint, created_at 2023_01_31, deployment Perimeter, former_category ADWARE_PUP, performance_impact Low, signature_severity Minor, updated_at 2023_01_31; target:src_ip;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP BoostBeast Task Request M2"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/api/"; startswith; content:"/task/get?browser="; distance:0; fast_pattern; threshold:type limit, count 1, seconds 120, track by_src; reference:url,tria.ge/230131-lezarafg93/behavioral2; reference:md5,fbdd33cf51fe4113000a7fc14908b56d; classtype:trojan-activity; sid:2044039; rev:1; metadata:attack_target Client_Endpoint, created_at 2023_01_31, deployment Perimeter, former_category ADWARE_PUP, performance_impact Low, signature_severity Minor, updated_at 2023_01_31; target:src_ip;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP BoostBeast Checkin M1"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/api/taskforecast/installed"; bsize:27; fast_pattern; http.content_len; byte_test:0,=,0,0,string,dec; reference:url,app.any.run/tasks/556c8a11-a736-48db-9779-bb74db2431c6/; reference:md5,73923a750344d1a1e734a12e98271c69; classtype:pup-activity; sid:2044040; rev:1; metadata:attack_target Client_Endpoint, created_at 2023_01_31, deployment Perimeter, former_category ADWARE_PUP, performance_impact Low, signature_severity Minor, updated_at 2023_01_31; target:src_ip;)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP BoostBeast Checkin M2"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/api/"; startswith; content:"/task/installed"; endswith; fast_pattern; http.user_agent; content:"HeadlessChrome/"; reference:url,tria.ge/230131-lezarafg93/behavioral2; reference:md5,fbdd33cf51fe4113000a7fc14908b56d; classtype:trojan-activity; sid:2044041; rev:1; metadata:attack_target Client_Endpoint, created_at 2023_01_31, deployment Perimeter, former_category ADWARE_PUP, signature_severity Minor, updated_at 2023_01_31; target:src_ip;)
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET ADWARE_PUP BoostBeast Task Response"; flow:established,to_client; http.stat_code; content:"200"; http.content_type; content:"text/plain|3b|"; startswith; http.response_body; content:"|7b 22|Id|22 3a|"; startswith; content:"|2c 22|Watch|22 3a|"; fast_pattern; content:"|2c 22|Action|22 3a 22|"; threshold:type limit, count 1, seconds 120, track by_src; reference:url,app.any.run/tasks/556c8a11-a736-48db-9779-bb74db2431c6/; reference:md5,73923a750344d1a1e734a12e98271c69; classtype:trojan-activity; sid:2044042; rev:1; metadata:attack_target Client_Endpoint, created_at 2023_01_31, deployment Perimeter, former_category ADWARE_PUP, performance_impact Low, signature_severity Minor, updated_at 2023_01_31; target:dest_ip;)

```

## Analysis

Very interesting find! This actually seems to be some sort of malicious program which forces a user to unknowingly watch or stream a YouTube Video or Live Stream. I did a pivot on the [IP address in VirusTotal](https://www.virustotal.com/gui/ip-address/79.137.206.202/relations) and found many related samples.

Sidnote: The most interesting youtube video I could find which was commanded, was located at `https://www.youtube.com/watch?v=3eWCZq94teo` This is an unlisted live stream titled “Test”.

I was able to identify three main activities which happen with the C2 server.

### Checkin

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/fe712e4211ec713f597bcb998d611744892b4963.png)

### Task Requests

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/0a4f12404b37b0c150bf625797ca8965b6be4f96.png)

### Exception Handling

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/eea4ecd923851d9caffd370d04c71781c1771fba.png)

### Distribution

In at least two cases it appears that this was delivered via SmokeLoader

- [0cfb92bbc7cd9e7887840871ac644479](https://www.virustotal.com/gui/file/5c8ffa48d181a6edab3c52473531959d479d8b2baece08168ce0a33a6eb2784e)
- [ffdb43a715539f0047dbea6187b710ce](https://www.virustotal.com/gui/file/83957bd8b55e9c20875c957fb809887fc2635618e8c0c6217999dbaa3805110d)

### Active Development

Using that same C2 server, I was able to find, what appears to be an updated version of the application. This sample appears to have been complied on Jan 27th of 2023.

- [fbdd33cf51fe4113000a7fc14908b56d](https://www.virustotal.com/gui/file/8e0a2bc6b7cb6a2531569d25e0708df76f0ea8a2cd52bc8ab3b090e08fed319b/details)

A very good sandbox execution can be found on [Tria.ge](https://tria.ge/230131-sdvphagg88/behavioral2)

While this version uses the same interactions (Checkin, Task Request, and Exception Handling) the format of them is slightly different.

#### Checkin

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/1dd34c20fc53612551d0e003bf3e1b3ebde6a165.png)

#### Task Request

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/be34f8ab46cacd86b999b4cbfde39be6a2e9e10f.png)

## Monitoring

If you wanted, you could actually monitor which video’s are being “commanded” via a simple curl to the c2 server. Fun stuff!

![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/b498a43856d980eea630fa68b97de12c116ef1bb.png)

## Rule Feedback

### Protocols

I’m guessing, based on the use of suricata keyworks (`http.uri`, `http.method`) these rules were written for Suricata. As such, it’s highly suggested to use the protocol associated with the traffic being inspected. In this case, the protocol of [`http`]( would be best.

### bsize

When you’ve got an “exact” match (like the URI in `sid:2008005`) the bsize keyword can be used to ensure the match is exact and can help optimize the fast\_pattern when used.

In this case adding the bsize:21 to `http.uri; bsize:21; content:“/api/taskforecast/get”;`

### Hex Encoding Special Characters

With this content match `content:"{"Id"";` there are a handful of “special” characters within Suricata’s (and snort’s) language that need to be hex encoded when used within a content match. The quote (`"`) is one of them and should be encoded using the `|22|` method.

From the [Docs](https://suricata.readthedocs.io/en/suricata-6.0.0/rules/payload-keywords.html?#content)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/b512b51affa2968c2d2ed5f93fa1c3c45a5195cb.png)
