typetechniqueconfidencehighcreated2026-08-17updated2026-08-17droppersfx7-ziparchive

7z-sfx-dropper

Repurposing the 7-Zip self-extractor (SFX) as a malware delivery mechanism. The SFX module is a legitimate PE binary that extracts an embedded 7-Zip archive and optionally runs a post-extraction command.

Configuration

The SFX config block sits between ,!@Install@!UTF-8! and ;!@InstallEnd@! markers in the .rsrc section or overlay. Key directives:

  • RunProgram="..." — executable to launch after extraction
  • InstallPath="%TEMP%" or "%ProgramFiles%" — extraction destination
  • GUIFlags, Progress, OverwriteMode — UI suppression options
  • ExtractPathText, ExtractTitle — social-engineering labels

Static Fingerprint

  • Strings: 7-Zip SFX, Copyright (c) 2005-2010 Oleg Scherbakov, 7zSfxMod
  • Version: 1.4.0 beta (7-Zip 9.15 beta) is a common builder
  • binwalk detects 7-zip archive data, version 0.4 at overlay offset
  • Extraction reveals one or more payload files (.exe, .dll, encrypted data)

Observed Samples

  • 642ecaab (INUS.exe) — SFX extracts Steam Error Reporter masquerade + encrypted companion files ^[raw/analyses/642ecaab/report.md]
  • ghostpulse — 7-Zip SFX containing Qt5 x64 payload and encrypted sidecar files

Related