Is 7z.sfx.exe safe?
No antivirus engine identified malware, and the completed sandbox found no offensive behavior, although unsigned status and one unresolved direct-IP connection warrant source verification.
All 74 antivirus engines returned no malicious or suspicious classification, including 17 tier-1 engines. One completed sandbox produced no malicious verdict or offensive techniques, but the unsigned executable contacted a direct IP whose reputation was not fully checked, so obtain it only from a trusted source.
5ac2a2579f402a0f7c…281aaa7fb0ca62Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines returned no malicious or suspicious classification, including 17 tier-1 engines. One completed sandbox produced no malicious verdict or offensive techniques, but the unsigned executable contacted a direct IP whose reputation was not fully checked, so obtain it only from a trusted source.
The strongest evidence is the absence of detections across 74 antivirus engines, with all 17 participating tier-1 engines reporting no detection. One completed sandbox recorded no malicious verdict, persistence, dropped files, or offensive-only techniques. The file has also appeared in 323 submissions from 292 sources over 101 days, providing more exposure than a newly encountered sample. Its unsigned status prevents publisher authentication, and one direct-IP connection remains unresolved because no complete host-reputation result is available. A community note about XOR-obfuscated import names is uncorroborated by engine detections or saved YARAify results and therefore carries limited weight.
What We Detected
None of 74 antivirus engines flagged the executable as malicious or suspicious. This includes 17 tier-1 engines such as Avast, BitDefender, ESET-NOD32, Kaspersky, and Microsoft. The file has been submitted 323 times by 292 sources over 101 days, giving scanners meaningful opportunity to identify a known threat.
Threat Behavior
One completed sandbox run produced no malicious sandbox verdict, no offensive-only techniques, no persistence indicators, and no dropped-file hashes. It did record a connection to 162.159.36.2, but the low-severity direct-IP heuristic is not enough to establish command-and-control traffic. Because contactedHosts is unavailable, no complete reputation assessment of that address can be made. The executable is unsigned, and a community annotation mentions XOR-obfuscated import names, but neither point is corroborated by malware detections.
What To Do Now
Confirm that the file came from the expected software publisher or a trusted download channel before running it. Keep endpoint protection enabled and rescan if the hash, source, or file behavior changes.
Where this verdict could be wrong3 caveats
- The executable is unsigned, so no authenticated publisher identity or established signer history is available.
- One sandbox recorded a direct connection to 162.159.36.2; contactedHosts=null leaves its reputation unresolved.
- communityComments[0] mentions SUSP_XORed_PE_ImportNames, but it has 0 votes and is not corroborated by externalIntel.yaraify.ruleCount=0 or antivirus detections.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines reported malicious or suspicious
- 17 tier-1 engines reported no detection
- One sandbox produced no malicious verdict and 0 offensive techniques
- No persistence indicators or dropped-file hashes were observed
- 292 sources submitted the sample 323 times over 101 days
- Unsigned Win32 executable with no authenticated publisher identity
- Direct-IP connection to 162.159.36.2 lacks a completed host-reputation check
- Community annotation references SUSP_XORed_PE_ImportNames without independent corroboration
- Filename 7z.sfx.exe does not clearly identify the observed NMSSaveEditor process context
Use the file only if its source and intended NMSSaveEditor context are expected, and verify its SHA-256 before execution. Keep endpoint protection enabled and avoid granting unnecessary privileges.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 12MITRE ATT&CK techniques
- 2spawned processes
- 1network contacts
- 0filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
7z.sfx.exe
5ac2a2579f402a0f7c654e1734ff1eb99f910c5db0a0f7c6eb281aaa7fb0ca62
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\NMSSaveEditor _1_.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\user\Desktop\NMSSaveEditor (1).exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
04Isolated runtime analysis
4 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 74engines flagged
- 292sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
One or more independent reference checks were incomplete or unavailable.
ProvenanceDerivedSourceExternal-intelligence coverageObserved at - 03
The hash has been submitted 323 times from 292 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: 7z.sfx.exe — 5ac2a2579f402a0f7c654e1734ff1eb99f910c5db0a0f7c6eb281aaa7fb0ca62
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\NMSSaveEditor _1_.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\user\Desktop\NMSSaveEditor (1).exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- 7z.sfx.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 63.9 MB
- Last analyzed
- Sep 15, 2026, 7:32 AM UTC
5ac2a2579f402a0f7c654e1734ff1eb99f910c5db0a0f7c6eb281aaa7fb0ca62Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is 7z.sfx.exe safe?
What is 7z.sfx.exe?
How many antivirus engines detected 7z.sfx.exe?
What is the SHA-256 hash of 7z.sfx.exe?
Is it safe to run 7z.sfx.exe?
How up to date is this analysis of 7z.sfx.exe?
Community
Member reviews and reports for this exact file hash.