In-depth Technical Analysis of Colibri Loader Malware
ID: 1a3f3745-0384-509d-85a7-12e31291807a
STIX ID: report--1a3f3745-0384-509d-85a7-12e31291807a
Feed Name: CloudSEK Blog
Threat Score
**Executive Summary:** The report analyzes Colibri, a Windows malware loader advertised on an underground Russian forum, detailing its packing, unpacking, self-modifying code, dynamic API resolution (avoiding an IAT), encrypted strings, and C2 communications to 80.92.205.102/gate.php; it provides MD5 hashes and network IOCs and concludes Colibri is a stealthy delivery mechanism capable of downloading and decrypting secondary payloads, posing a high risk as a malware loader.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
