logo

Doing time with the YIPPHB dropper

ID: 5596e49f-9230-5ee6-babc-4b4c4d06ab0b

STIX ID: report--5596e49f-9230-5ee6-babc-4b4c4d06ab0b

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2022-11-21

Date Updated: 2026-04-27

...
...

This Elastic Security Labs analysis details an intrusion set (REF4526) that uses creative PowerShell obfuscation (Unicode icons inside Base64 strings replaced at runtime) to download a .NET loader, a YIPPHB dropper, and RAT implants (NJRAT/LIMERAT). The report documents the loader/dropper/RAT phases, provides decoded IOCs (SHA-256 hashes, TinyURL and Discord-hosted URLs, and a C2 domain), clusters of related activity, and practical collection/hunting procedures and queries to detect similar activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.