Self-extracting 7z archive auto-runs embedded payload on extract
Self-extracting archives unite a compressed payload with a small executable stub, so opening one both unpacks data and immediately triggers whatever code it embeds. Attackers lean on this to deliver initial access, since a .7z/.exe carrier slips past filters that block direct executables while still running the payload without user action. Here a benign stub is configured to launch Calculator on extraction, proving the extract-and-execute chain can fire silently. The Archive Engine inspects the self-extracting structure, recursively unpacks and scans every layer, and examines the embedded executable before anything is allowed to run. By validating the archive at the gateway, MetaDefender stops the payload from ever reaching the endpoint.
Attack Technique
Self-extracting archive
MITRE ATT&CK
T1027.003 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗