logo

In-depth Technical Analysis of Colibri Loader Malware

ID: 1a3f3745-0384-509d-85a7-12e31291807a

STIX ID: report--1a3f3745-0384-509d-85a7-12e31291807a

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2022-03-10

Date Updated: 2026-04-27

...
...

**Executive Summary:** The report analyzes Colibri, a Windows malware loader advertised on an underground Russian forum, detailing its packing, unpacking, self-modifying code, dynamic API resolution (avoiding an IAT), encrypted strings, and C2 communications to 80.92.205.102/gate.php; it provides MD5 hashes and network IOCs and concludes Colibri is a stealthy delivery mechanism capable of downloading and decrypting secondary payloads, posing a high risk as a malware loader.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.