TF-1932606
high
📛 Threat Title
Colibri Loader: URL that is used for botnet Command&control (C&C) http://212.109.218.20/gate.php
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Colibri Loader. Confidence: 100. First seen: 2026-09-25 03:00:20 UTC. Reporter: abuse_ch. Tags: ColibriLoader.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://212.109.218.20/gate.php
IOC database
- Type
- url
- Value
http://212.109.218.20/gate.php- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Colibri Loader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Colibri Loader. Confidence: 100. First seen: 2026-09-25 03:00:20 UTC. Reporter: abuse_ch. Tags: ColibriLoader.
Remediations (10)
-
web:boteraser.com
Colibri Loader is a modular malware loader first publicly documented in December 2021 by researchers at Zscaler ThreatLabz, believed to be developed and operated by a Russian-speaking cybercriminal group known as TA551 (also tracked as UNC3059) for distributing secondary payloads including Cobalt Strike, Bumblebee, and IcedID.
-
web:ctiwatch.com
Colibri Loader is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
-
web:ctiwatch.com
Colibri Loader is a malware family tracked by threat intelligence researchers and catalogued in the Malpedia dataset. It represents a distinct malicious software lineage with identifiable code characteristics, behaviors, and victimology.
-
web:infocon.org
Between July and October 2022 BitSight observed a ColibriLoader malware campaign being distributed by PrivateLoader, which was identified as being utilized by the threat actor UAC-0113, a group linked to Sandworm by CERT-UA. Sandworm is known to be a Russian advanced persistent threat (APT) group affiliated with The Main Directorate of the General Staff of the Armed Forces of the Russian ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to cloudsek, Colibri Loader is a form of malware designed to facilitate the installation of additional malware types on an already compromised system. This loader employs various techniques to evade detection, such as excluding the Import Address Table (IAT) and utilizing encrypted strings to complicate analysis. Similar to other loader malware, Colibri can be utilized to deploy ...
-
web:socprime.com
The initial version of Colibri Loader that was created last summer, was delivering an EXE file with a self-modifying code through trojanized files. In an ongoing campaign, the attack chain also starts with an infected Word document that launches the operation of a Colibri bot and establishes an unusual persistence tactic.
-
web:support.trellix.com
The threat actor behind the loader dropped a copy of Colibri as Get-Variable.exe in the WindowsApps directory causing PowerShell to execute the malicious executable instead of the valid PowerShell Get-Variable cmdlet. Our ATR Team gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports.
-
web:www.bitsight.com
In this research, we present how to manually "unpack" a sample from a recent ColibriLoader malware campaign being distributed by PrivateLoader.
-
web:www.cloudsek.com
Technical Analysis of Colibri Unpacking the loader Colibri loader comes packed in a trojanized executable file. By using x64dbg (debugger) and putting breakpoints on the function VirtualAlloc we were able to extract the actual payload of the Colibri loader .
-
web:www.threatdown.com
Colibri Loader is a relatively new piece of malware that first appeared on underground forums in August 2021 and was advertised to " people who have large volumes of traffic and lack of time to work out the material ". As it names suggests, it is meant to deliver and manage payloads onto infected computers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.