7z-sfx-dropper
Repurposing the 7-Zip self-extractor (SFX) as a malware delivery mechanism. The SFX module is a legitimate PE binary that extracts an embedded 7-Zip archive and optionally runs a post-extraction command.
Configuration
The SFX config block sits between ,!@Install@!UTF-8! and ;!@InstallEnd@! markers in the .rsrc section or overlay. Key directives:
RunProgram="..."— executable to launch after extractionInstallPath="%TEMP%"or"%ProgramFiles%"— extraction destinationGUIFlags,Progress,OverwriteMode— UI suppression optionsExtractPathText,ExtractTitle— social-engineering labels
Static Fingerprint
- Strings:
7-Zip SFX,Copyright (c) 2005-2010 Oleg Scherbakov,7zSfxMod - Version: 1.4.0 beta (7-Zip 9.15 beta) is a common builder
binwalkdetects7-zip archive data, version 0.4at overlay offset- Extraction reveals one or more payload files (
.exe,.dll, encrypted data)
Observed Samples
642ecaab(INUS.exe) — SFX extracts Steam Error Reporter masquerade + encrypted companion files ^[raw/analyses/642ecaab/report.md]- ghostpulse — 7-Zip SFX containing Qt5 x64 payload and encrypted sidecar files