Our call: Is 7z.sfx.exe safe?Safe
Zero malicious detections across 74 engines, medium prevalence, and no sandbox malicious verdict.
- 0 of 74 antivirus engines flagged the file.Observed · Antivirus analysis
- The hash has been submitted 995 times from 873 sources.Derived · Saved report facts
f528db8cf63ebd5808…2ce8ea04acRecommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
7z.sfx.exe
f528db8cf63ebd580886c747bff7ca2de69644307724738eea3de22ce8ea04ac
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\cslol-manager-windows _4_.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\user\Desktop\cslol-manager-windows (4).exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
04Isolated runtime analysis
4 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 995 times from 873 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: 7z.sfx.exe — f528db8cf63ebd580886c747bff7ca2de69644307724738eea3de22ce8ea04ac
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Users\<USER>\Desktop\cslol-manager-windows _4_.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — "C:\Users\user\Desktop\cslol-manager-windows (4).exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 engines returned clean results with 17 tier-1 engines explicitly marking the file harmless. The file is unsigned and contacted one external IP, but no malicious sandbox verdict or known-bad host reputation is available.
The complete absence of malicious detections from every engine tier, including 17 tier-1 engines reporting clean, is the dominant signal. Medium prevalence across nearly a thousand submissions indicates the file is not rare or newly observed. While the file is unsigned and triggered a low-severity direct-IP heuristic, the heuristic itself notes this pattern occurs in legitimate installers, and no sandbox malicious verdict or dropped malicious children exist.
What We Detected
74 antivirus engines scanned the sample; none flagged it malicious. 17 tier-1 engines explicitly returned clean. The file is an unsigned 37 MB Win32 executable first seen 108 days ago and observed from 873 distinct sources.
Threat Behavior
One sandbox execution recorded ambient system-discovery and evasion techniques but zero offensive MITRE techniques and no malicious sandbox verdict. The sample contacted IP 162.159.36.2 directly; host reputation cross-check coverage is unavailable. No dropped children or persistence mechanisms were observed.
What To Do Now
Keep endpoint protection enabled. The file shows no malicious indicators in our analysis. If the file was obtained from an untrusted source, obtain a fresh copy from the original publisher before execution.
Where this verdict could be wrong3 caveats
- One community comment tags the file with trojan/spyware keywords, but no engine detections or sandbox malicious verdict support that label.
- Direct-IP contact to 162.159.36.2 triggered a low-severity heuristic, yet the rule explicitly states this pattern also occurs in legitimate installers.
- File is unsigned; absence of a trusted publisher leaves no historical signer reputation to rely on.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines malicious
- 17 tier-1 engines reported clean
- Medium prevalence across 873 sources
- No malicious sandbox verdict
- File is unsigned
- Direct-IP contact observed (host reputation unavailable)
The evidence supports treating the file as safe for normal use; continue running current endpoint protection.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- 7z.sfx.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 35.6 MB
- Last analyzed
- Aug 1, 2026, 9:21 PM UTC
f528db8cf63ebd580886c747bff7ca2de69644307724738eea3de22ce8ea04acSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
Run it only when it came from the developer's official site or another source you independently trust.
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
Keep your antivirus and Windows updates switched on so you stay protected.