Skip to main content
← Back to Demos
Archive Abuse intermediate · 15 min

Self-extracting 7z archive auto-runs embedded payload on extract

Self-extracting archives unite a compressed payload with a small executable stub, so opening one both unpacks data and immediately triggers whatever code it embeds. Attackers lean on this to deliver initial access, since a .7z/.exe carrier slips past filters that block direct executables while still running the payload without user action. Here a benign stub is configured to launch Calculator on extraction, proving the extract-and-execute chain can fire silently. The Archive Engine inspects the self-extracting structure, recursively unpacks and scans every layer, and examines the embedded executable before anything is allowed to run. By validating the archive at the gateway, MetaDefender stops the payload from ever reaching the endpoint.

Attack Technique

Self-extracting archive

MITRE ATT&CK

T1027.003 ↗

Platforms

linuxwindows

File Types

.7z

MetaDefender Capabilities

Archive Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---