ComLook

First seen
2022-01-12 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 14:54:29

Targeted industries: government-and-public-sector

Targeted regions: country_code:az

Context

ComLook is a malicious plugin for the mail client "The Bat!", written in C++ and compiled with MSVC 10.0. It implements malicious commands like PutFile, GetFile, SetConfig, GetConfig, and Command. It contains hard-coded email addresses and other information, indicating a target in Azerbaijan. It was first uploaded to VirusTotal on January 12, 2022, and is associated with the APT group Turla. It appears to be a targeted deployment.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Turla_Comlook (yara-rule)
  • MALPEDIA_Win_Comlook_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Comlook (report)
  • msreverseengineering.com — An Exhaustively Analyzed Idb For Comlook (report)
  • twitter.com — 1484211242474561540 (report)

External references