7z.exe

by Igor Pavlov
Application

Sources: 300M+ executions observed in the wild and observed in the EchoTrail lab on Windows 11.

Summary

7-Zip - file archiver with high compression ratio supporting 7z, ZIP, RAR, and other formats.

7z.exe is the 1061st most commonly executed Windows program in EchoTrail's dataset, observed 1,779 times across enterprise environments. It typically runs from C:\Program Files (x86)\ManageEngine\UEMS_Agent\bin and it is most often launched by dcmsghandler.exe.

Get this in your tools

The same record for 7z.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/7z.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

1061st
most commonly executed Windows program
1,779
observed endpoint executions

Behavior

Top Paths

  • C:\Program Files (x86)\ManageEngine\UEMS_Agent\bin44.41%
  • C:\...14.05%
  • C:\Users\...12.42%
  • C:\Program Files\Unity\Hub\Editor\2019.1.5f1\Editor\Data\Tools12.03%
  • C:\Program Files\7-Zip8.99%
  • C:\ProgramData\...4.55%
  • C:\Program Files\Unity\Editor\Data\Tools1.35%
  • C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience1.01%
  • C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience0.39%
  • C:\Program Files\AMD\CNext\CNext0.17%

Top Hashes (SHA256)

  • a20d93e7dc3711e8b8a8f63bd148ddc70de8c952de882c5495ac121bfedb749f45.52%
  • c7245e21a7553d9e52d434002a401c77a7ca7d0f245f2311b0ddf16f8f946c6f12.59%
  • ae78a8f0f144eb50b4d5251ee8166557e1ffdc776c3806adce2a954f99f7ac3b12.3%
  • 344f076bb1211cb02eca9e5ed2c0ce59bcf74ccbc749ec611538fa14ecb9aad211.84%
  • eb021240d46f6c12e53fcf92f095ee87aae055a82ae0d986318e8f8b57e463cb6.78%
  • 5d359c7f2d3594fb9e32554aa7acea767231ea6bfa693c2f31415a79377ea65c4.48%
  • 47462483fe54776e01d8ceb8ff9fd5bf2c3f1f01d852a54d878914f62f98f2d33.74%
  • 907a9e5e8f67c66745088804e5ff6b66939ab3113567d96074a4778b0f95dd410.46%
  • 3b914d023fd198f395009552d977f4ff77a0187496f790a1298ffdecb94a46b60.4%
  • 043489c3481b20fef8b226b9bac2fad96fc6450f9ae69eed47ff0e226a55c4da0.23%
  • 6ee3c0ed0b27663c1b948ae85a7c0bb073aed1498983182f3f0df1f6a8c30b2f

Process Ancestry

Top Grandparents

Top Parents

Top Children

Lab record

Installed from
winget 7zip.7zip 26.03
Publisher
Igor Pavlov, unsigned
Persistence
none
Network
none
Command lines
6 patterns (18 launches)
DLL loads
19 patterns (317 loads)
Registry writes
2 patterns (21 writes)
File writes
12 patterns (36 writes)
HTTP requests
0 patterns (0 requests)
TLS connections
0 patterns (0 handshakes)
Named pipes
0 patterns (0 events)
Process access
0 patterns (0 events)
Driver loads
0 patterns (0 loads)
PowerShell blocks
0 patterns (0 blocks)
Remote threads
0 patterns (0 events)
Audit events
0 patterns (0 events)

Full record on Team.

Security Analysis

What does 7z.exe normally do?

7z.exe is the console front-end of 7-Zip and is expected to create, list, test and extract archives (7z, zip, tar, gz, iso, etc.) using 7z.dll from its install directory. In the lab it was installed via the winget package 7zip.7zip (the silent installer C:\lab\in\7z2603-x64.exe /S launched from PowerShell), which wrote the standard C:\Program Files\7-Zip tree (7z.exe, 7zG.exe, 7zFM.exe, 7z.dll, SFX modules, Lang\*.txt) and registered shell context-menu/drag-drop handlers under HKCR (CLSID {23170F69-40C1-278A-1000-000100020000}). Runtime activity was purely local: 7z.exe spawned only conhost.exe, performed add (a), list (l) and extract (x -o) operations against files under C:\Users\lab\labwork, and generated no network traffic of its own trn observed connections belonged to winget.exe, powershell.exe, svchost.exe and backgroundtaskhost.exe. No autoruns or scheduled tasks were created, and the binary is interactive/on-demand rather than persistent.

When is 7z.exe suspicious?

Execution of 7z.exe from a non-standard path (%TEMP%, %APPDATA%, %PUBLIC%, C:\Users\Public, ProgramData) or renamed (e.g. a.exe, svchost.exe) while retaining the 7-Zip console version-info; a portable 7z.exe/7z.dll pair dropped shortly before use. Command lines that archive whole user or server data stores for example 'a -mx0 -r' over C:\Users, Documents, Desktop, Outlook .ost/.pst, Sharepoint/network shares, or Hyper-V/SQL directories especially with volume-spanning (-v100m) and password flags (-p<complex>, -mhe=on) producing multi-part archives in staging directories. Parent processes that are not a shell driven by a human: wmiprvse.exe, services.exe, w3wp.exe, sqlservr.exe, rundll32.exe, mshta.exe, cmd.exe /c spawned by a remote-exec tool, or PsExec/SSH sessions; execution under SYSTEM or a service account. Use of 'x -y -o' into startup folders, IIS/webroot paths, or extraction of a password-protected archive immediately after a mail/browser download; use of -sfx to build a self-extracting executable; suspicious archive names such as 1.7z, out.zip, log.rar in C:\Windows\Temp. Large archive creation followed within minutes by outbound transfer (rclone, curl, MEGA/Dropbox clients, FTP) or by exfil-sized uploads.

How do attackers abuse 7z.exe?

7z.exe is one of the most common archiving utilities in real intrusions. Ransomware and extortion crews (Conti, BlackCat/ALPHV, Karakurt, BianLian, Akira, Cl0p, LockBit affiliates) routinely drop a portable 7z.exe+7z.dll and run 'a -mx1 -v5g -p<pass>' over file servers, user profiles and mail stores to stage and split terabytes of data for exfiltration to MEGA/rclone/FileZilla. APT and espionage actors (APT28, APT29, APT41, Lazarus, Mustang Panda, Gamaredon, FIN7) use it the same way to compress collected documents, screenshots and keylog output into password-protected archives that evade content inspection and DLP. It is used to bundle and hide toolkits: attackers ship encrypted 7z/zip payloads that AV cannot inspect and unpack them on-host with 'x -p<pass> -o<path>', a very common phishing chain (password-protected archive attachment). Credential-theft operators compress hive dumps, NTDS.dit, LSASS dumps or browser profile folders before pulling them down. The SFX feature (7z.sfx / -sfx switch) is abused to build self-extracting droppers, and modified SFX archives can auto-run embedded payloads; the 7-Zip installer directory also presents DLL side-loading opportunities for 7z.dll when 7z.exe is run from an attacker-writable folder. 7z.exe additionally serves as a quiet file-read/copy primitive (archiving locked or ACL-restricted-by-path files) and for anti-forensic packaging of logs before deletion.

Detection guidance

Baseline 7z.exe to C:\Program Files\7-Zip\ (and legitimate portable installs) and alert on the console binary executing from user-writable paths, under a service/SYSTEM context, or renamed match on OriginalFileName 7z.exe rather than image name. Hunt command lines containing the password (-p), header-encryption (-mhe), volume-split (-v), recursion over profile/share roots, or 'x -o' into startup, webroot or temp directories, and correlate archive creation events with subsequent large egress or cloud-storage client activity within a short window. Watch for unusual parents (wmiprvse.exe, w3wp.exe, mshta.exe, rundll32.exe, remote-exec/PsExec service processes) since the lab baseline shows only interactive shell parents and a conhost child, and flag creation of .7z/.zip/.001 files in C:\Windows\Temp, ProgramData or admin-share staging folders. File-integrity monitoring on C:\Program Files\7-Zip\7z.dll and alerts on 7z.exe loading a 7z.dll from a non-install directory will catch side-loading; also review SFX creation (-sfx, 7z.sfx/7zCon.sfx reads) as a packaging-for-delivery signal.

MITRE ATT&CK techniques

References

Ask Rocky about 7z.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for 7z.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.