s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932606 high

📛 Threat Title

Colibri Loader: URL that is used for botnet Command&control (C&C) http://212.109.218.20/gate.php

Category: Colibri Loader Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Colibri Loader. Confidence: 100. First seen: 2026-09-25 03:00:20 UTC. Reporter: abuse_ch. Tags: ColibriLoader.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url http://212.109.218.20/gate.php

IOC database

Type
url
Value
http://212.109.218.20/gate.php
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that is used for botnet Command&control (C&C) attributed to Colibri Loader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Colibri Loader. Confidence: 100. First seen: 2026-09-25 03:00:20 UTC. Reporter: abuse_ch. Tags: ColibriLoader.

Remediations (10)

  • web:boteraser.com

    Colibri Loader is a modular malware loader first publicly documented in December 2021 by researchers at Zscaler ThreatLabz, believed to be developed and operated by a Russian-speaking cybercriminal group known as TA551 (also tracked as UNC3059) for distributing secondary payloads including Cobalt Strike, Bumblebee, and IcedID.

  • web:ctiwatch.com

    Colibri Loader is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

  • web:ctiwatch.com

    Colibri Loader is a malware family tracked by threat intelligence researchers and catalogued in the Malpedia dataset. It represents a distinct malicious software lineage with identifiable code characteristics, behaviors, and victimology.

  • web:infocon.org

    Between July and October 2022 BitSight observed a ColibriLoader malware campaign being distributed by PrivateLoader, which was identified as being utilized by the threat actor UAC-0113, a group linked to Sandworm by CERT-UA. Sandworm is known to be a Russian advanced persistent threat (APT) group affiliated with The Main Directorate of the General Staff of the Armed Forces of the Russian ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to cloudsek, Colibri Loader is a form of malware designed to facilitate the installation of additional malware types on an already compromised system. This loader employs various techniques to evade detection, such as excluding the Import Address Table (IAT) and utilizing encrypted strings to complicate analysis. Similar to other loader malware, Colibri can be utilized to deploy ...

  • web:socprime.com

    The initial version of Colibri Loader that was created last summer, was delivering an EXE file with a self-modifying code through trojanized files. In an ongoing campaign, the attack chain also starts with an infected Word document that launches the operation of a Colibri bot and establishes an unusual persistence tactic.

  • web:support.trellix.com

    The threat actor behind the loader dropped a copy of Colibri as Get-Variable.exe in the WindowsApps directory causing PowerShell to execute the malicious executable instead of the valid PowerShell Get-Variable cmdlet. Our ATR Team gathers and analyzes information from multiple open and closed sources before disseminating intelligence reports.

  • web:www.bitsight.com

    In this research, we present how to manually "unpack" a sample from a recent ColibriLoader malware campaign being distributed by PrivateLoader.

  • web:www.cloudsek.com

    Technical Analysis of Colibri Unpacking the loader Colibri loader comes packed in a trojanized executable file. By using x64dbg (debugger) and putting breakpoints on the function VirtualAlloc we were able to extract the actual payload of the Colibri loader .

  • web:www.threatdown.com

    Colibri Loader is a relatively new piece of malware that first appeared on underground forums in August 2021 and was advertised to " people who have large volumes of traffic and lack of time to work out the material ". As it names suggests, it is meant to deliver and manage payloads onto infected computers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.