URLhaus Database

You are currently viewing the URLhaus database entry for http://update.cg100iii.com/cgmb/Update.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3337012
URL: http://update.cg100iii.com/cgmb/Update.exe
URL Status:flame Online (spreading malware for 1 year, 5 month, 25 days, 10 hours, 36 minutes)
Host: update.cg100iii.com
Date added:2024-12-08 16:37:37 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2026-05-18 19:01:24 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-16Update.exeexe 07beac97b54c7683423caec56c1e7828a92df9298fc04e73c0f0e19e1149a7f3n/a 
2025-04-06Update.exeexe aec97a5620cadb6a7710485a0ae66cd05677c799a60a1a4b888bfc0f8a3cabd9n/a 
2025-03-15n/aexe 7c6a3dadb65fda825a54c6e7f8812d4dcb8efd341290b02a001213d3c59e19aen/a 
2025-03-15n/aexe ba777a4753b5ef3946d54c293133e98a07d540549e586f3babf2a0c2bc490932n/a 
2025-03-15n/aexe 5ed3a3083227901190125238672335b9d09bfa96ca74915076fd7b7107974a07n/a 
2025-02-27n/aexe b3b5b9fa341b58a19c77b324f7f59f296cd8edc607598dd9ffb7000db5112d17n/a 
2025-01-28n/aexe bddfac8394f53abbc47067454e8d8944b4569794723eed80fe26e26eb273ad34n/a 
2025-01-25n/aexe 0a45864871502634ebd37e32c62b12fe9751dc08b0a58e85d2451134a9a4e2fbn/a 
2024-12-28n/aexe c451dea79f46462e0305483c8563df8702f01ea27c12b3f10a0cfbd8b1c614c3n/a 
2024-12-16n/aexe 1df60a63c8806317c1761d9c5bbfa22afb9117b5983196cf30774864c5d6c190n/a 
2024-12-08n/aexe 40803ec9aa1c83e4b3c286d93899cc006b9e9cf4aca44b7eabc8bf16ee31ec57Virustotal results 31.94%