7zip.exe

The application 7zip.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.headsharecity.com and multiple other hosts.
MD5:
bbb7482c658d2a976a0670b628d11658

SHA-1:
e4a1ae547f559129029fd79f971f513d32b10caa

SHA-256:
7c0281a82f92299b8e351ec031adc5c409b2ff2247c915f0ac1868d213be6b90

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/6/2025 3:23:42 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Detection.Undefined
7.0.302.0

Reason Heuristics
PUP.Bundle.Offer
16.3.1.10

SUPERAntiSpyware
Trojan.Agent/Gen-Agent
9935

File size:
1.1 MB (1,200,163 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\7zip.exe

File PE Metadata
Compilation timestamp:
10/6/2014 11:40:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:1KNlBcA+5X41xfn72wx+jaHNm9yPyduBM95vNFzIo3AQNR8s1H9+:QNrl+R/OmgPydzXvDzIo37NRd+

Entry address:
0x30E2

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 78, E4, 42, 00, E8, A8, 2D, 00, 00, A3, C4, E3, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 00, 88, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, DB, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 40, 2A...
 
[+]

Entropy:
7.9940

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file 7zip.exe has been seen being distributed by the following 50 URLs.

http://www.headsharecity.com/WVl6OTRQU1V5UWpSdU1FSk9kMFpoYTJKS2EycHdhakF5UTBaeE1YZHFPVlpMWlc1RU9HOU9TR1JzUWxSeE1VVmlOQ1V6UkNaalBVbFdXVmg0VkZNd1JrOU1la0pJU1VKYWNXTk9kVlY1WTIxUWVYTXdURFFsTWtaWWJHcGFkekl5ZDBkQk9VaHpORWR1UjI4MFJreG5ObGRzUjFCc1kxTnFibWxRVURKMGFUWlhkemd3U25WcEpUSkdUR3RsTURkR2NqaGliR2hQU1haSmExbHBiMjQySlRKQ1oyTnNlalZXTUhObFltVmxOMjFPY21GM1NXUmxTV0ZGV0Vzd0ptUnZkMjVzYjJGa1FYTTlhVzV6ZEdGc2JDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ptYVd4bGN5NW5aVzVwZFhNdGNtOTFkR1Z5TG1OdmJTVXlSamQ2T1RNNExtVjRaUT09

http://www.repositoryappsupdate.com/WVl6OTRQV1pFTkNVeVFtZzBSR05sTUdGT01FSTVUbnB4YlU1V1MySldTa0l3YkRodlpWUTVSMWQ0YUdVMlRHMXVXU1V6UkNaalBUaDRaMXBqUmpFMGVHY3dNRm8yUldaamFUTnZXa0Z5T0V0RmQzb3pUWGx5UzBaSVZWTlhabXR3UjBaRmNFa3pORTVaYmpSTmQyeEtWVEZRVEVOM1pXbG1NRmd6UVdWREpUSkNhMjEwTld0dWRGbzBkSFp2ZDNGbmJGaEpNSEJtV1dzMGN5VXlSakpEVFZrbE1rWnhWR2xuWjA1RE5rOVVXVVExYnpkV1oydFhaRU54V2xsSkptUnZkMjVzYjJGa1FYTTlhVzV6ZEdGc2JDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ptYVd4bGN5NXpkSGxzWlcxNWMyVnNaaTV1WlhRbE1rWTNlamt6T0M1bGVHVT0=

http://www.bestappshost.com/WVl6OTRQVFpwVERVMlYyaEljbmxRU1dKelFqQjZWU1V5UmpaVU0xRTBhekkwY0ZZbE1rWTNTRGx1U0hKTFRsWkJaMkYzSlRORUptTTljMFY1UmpVeFVESndjMDFLT0hJNVRsZFZWMFpVWjFkNkpUSkNZakZuVWtnM1RFRm5NM2xhUm1jbE1rWmFNbVUwT0VSS1JWWWxNa1pMUzA5MFVsbG9Uakp2YUhsMmFIbGFRMjlxYVhSeFpXRm9VREZIZUhSdWMxTjVTa2xsZVUxUVExUlplbk0yYTJKWFRVRlhZVkl4VkVodk1YZGFNVzFEWTFwNmVFTmhXbWxGV1VjMWVYTW1aRzkzYm14dllXUkJjejFwYm5OMFlXeHNMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1acGJHVnpMbk4wZVd4bGJYbHpaV3htTG01bGRDVXlSamQ2T1RNNExtVjRaUT09

http://www.bestappshost.com/WVl6OTRQVU1sTWtaa1NsZFpVM1pGVlRaRlRqZEZiMEpZTVZBd2VVOTBURmxPTVZaSE4ydEZTRk0yY0dVbE1rSnBjSGRaSlRORUptTTlWM2xVY1dOUk5HaHJWMWNsTWtJeFJTVXlRbVZzU3pKd1ZXMXhhRzVqVTBaeWNqQXpZbGhuYnpaRFN6QnpRM0p1Y1VwS2FpVXlSaVV5UWtWVGEwUjNkMmg2VDBaM01VSTRUVkJHY2pCbU9GWTNhell4YkdacE1YRlNWMjlYTjI5cVkxTnNaMVZVUVRWSWFFaDZOVFJ2YWs1M2NuRTFSM3BSV25WcGVFUkpaWFJHY1c5YWMwTnRNaVprYjNkdWJHOWhaRUZ6UFdsdWMzUmhiR3d1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR1ptbHNaWE11YzNSNWJHVnRlWE5sYkdZdWJtVjBKVEpHTjNvNU16Z3VaWGhs

http://www.grabdeliverybits.com/WVl6OTRQVnBaZFhjbE1rSm5iVnBJTm5oWlFXWldUbXB3T1dwUU1WRlVhWHBOWVZneFlXdExOalIyZFZVeGQyVlVieVV6UkNaalBWVjJTV042ZFVwWFdtRmxVbk1sTWtaWmVERjVUbUZaVG1wdVVFTlJiMGNsTWtKaVRUbEVXSGg1VWtoRGFXWnFiSEZtYjJJd1RDVXlRbmxTTm0xeWNsUklZVFpZV1daV1UzUlpVRzF5VTA5S1pFNTBUMVpTTVVsNGRHWTRNazVHY0ZKd1ptYzBWVzl6WjBsbGVreENXV2xSTmtSaFMwVjJjSFJzTnpKQk55VXlRbmhYWnpJNGVIa21aRzkzYm14dllXUkJjejFwYm5OMFlXeHNMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1acGJHVnpMbk4wZVd4bGJYbHpaV3htTG01bGRDVXlSamQ2T1RNNExtVjRaUT09

http://www.citycleartower.com/c?x=7YqBHavbNj9ZKaZzdzDf7PDDC YOSQnasZCWiF/V kI=&e=0&c=vH4Ic1Cjlo GNXvrBM6vNopoPaHodUYqDHKbRmkrUw66g U/5zc3SW5upv78mZ3aNJcjWyqvSeNZ3HBOjAUwfAhxsedHf1saSYu7BBZz90JopNwLzpCm6cRy4Lo4YHUxrFTLBagAlhJtKdFIgzzssYjBiVgKhbwK/v/jbipPe60=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.repositoryappsupdate.com/WVl6OTRQVTVhYTNsWVUxQklhSEpJYWtocllXZEdSVVpVUzNaVk1tZE1WMWRGYUdOck5Hd3hjM0JEU1cxNmJsVWxNMFFtWXoxMFF6SjZVbEV4TkVsemNtOVVkQ1V5UWpocE9UQmpWazB5YkROTmVqRndUM1FsTWtJNFMzZHFjVWszV1ZZbE1rWXhkR050U1cxVGNWcEpSazlhTUhGTVpGWldTbHBwVWtKQmFVMUtRM3B5TTB0U1drdHNXV3hIYUZVd2NrbGhheVV5UmpSM2VtaHhVV3BXTlVZM056WkhjU1V5UW5GNWRHOW9NR2hhYVdJbE1rSXdORmhaY0Vvek9USkthU1prYjNkdWJHOWhaRUZ6UFdsdWMzUmhiR3d1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR1ptbHNaWE11YzNSNWJHVnRlWE5sYkdZdWJtVjBKVEpHTjNvNU16Z3VaWGhs

http://www.presentdownloadshead.com/WVl6OTRQVkJYSlRKQ1NrSTBiMjlXY0c5eGFFOUpaV2hUWkRkRkpUSkdSV3BTVkZkalZtUlFkME5uVFV4VkpUSkNUMFoyVEZVbE0wUW1ZejFSY3pVeFJrdGxSVVZVZEVkaE5YVTFNRmxhYTJZd1RrVWxNa0pCZVZSUU9WVlFiVE00WkVSc2MweEtVR1ZXT0hwM0pUSkNNVk5wYmxOcWNHWjVaekJCTTBSbVZVWlRTVUpWZGt4RE5EWnhUVzFYTm5GUGJuQnRRVTFhUVVsT01EUk9ZM2xOUlhBMFltRnhabTVGVEhSclJHZEdUR04zY1VNeU9YZEtKVEpHZEdsNVExaEZTaVprYjNkdWJHOWhaRUZ6UFdsdWMzUmhiR3d1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR1ptbHNaWE11YzNSNWJHVnRlWE5sYkdZdWJtVjBKVEpHTjNvNU16Z3VaWGhs

http://www.citycleartower.com/c?x=QmGdRomM9Pae1JTG3/y9V80WFFEQ23InPlHnr7n85Y4=&e=0&c=J/W2dnkC/LNPAxcdVWyXOaWZ8xR28zM6TSr6jJRDU9Y/8HZHjR7gJJm8Du288CS1ChLYR7 3ulZetjyGJanAycjYz6DrALrzFnG36EPwd2D8SCTLpdWE1Gt6iFYYS7nY14JTuVxTvmbBBj1Sr2aof6LU2cFWBt0tPyb1k7VmGDU=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.citycleartower.com/c?x=UG4Jgr02mqINtHxPr81u v gqIBc3nP7NWj7WOxDecw=&e=0&c=onawfFxdIea8 lPkn0C6EQyAYzts2PF5NKbWt46x7v1mUgFnMOoyGkgr14pX2ZH6izbhZX/OE3GbYagID Gdk5m7BBlnzBrUevfVVeFx5FcP9NWmvDaLDwAf0KY6CqkZij5j/XwUMNwV0tNN u8/3bp47IEgNtbB/DTIAl5yp78=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.citycleartower.com/c?x=8nOAMhCZKpS5/HnSC5ltwlcTAmc9046Zj4CUMoxnFRk=&e=0&c=7KgIGVAPX43btjYx9VY3eB2UlksC6 i7 bF5drIN193jz7iwjwQugNNIr7Nkx/PYNldnFf7qk81lTGpKEFaw gM 2xCxgbI4vLGY7VS02OsefU3piAmkJWIpz/OkJgyW0QmlRZpf1zdUd3REr7RYpnC4bhhLdVfXJE8u JEdPA8=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.grabworldgift.com/WVl6OTRQVVJYYTI5QlMyOU5KVEpHZWxaVWJpVXlRa2xoUnpOblR6QnRTVzlRT1doWFEzRTBOemxKVTBSc2VWcFBSWHBKSlRORUptTTlOMU5UY0RoWVpEZHFVMDk1U1hwNk1EZEdXbGRFTkc0NWJtNVBXSEZ4WmxGWWJtTlVRME5oT1hkeldUWkJOVlpIWlVoTWNqSk1lalYwZERaUE9ITk1jMVUyTnpCalpFWTBUV3AzWjJvelpHd3labkZVU1ZscE4zQTNUVXBtYkdWdFlucDRXVkpKWmtkNWRHTWxNa1pRTUd0SmRYQlpUMDg0TjJWWU9EZE5Xa1p3U1Naa2IzZHViRzloWkVGelBXbHVjM1JoYkd3dVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdabWxzWlhNdVoyVnVhWFZ6TFhKdmRYUmxjaTVqYjIwbE1rWTNlamt6T0M1bGVHVT0=

http://www.repositoryapplicationscity.com/WVl6OTRQVFIxZDFkUlRIUllabWxMV0dsblpFMU1UMjUzZDJkRWMyaFpXVXBaZFhOaE9WZDNSSGhhU0hVemJYTWxNMFFtWXoxUFQwVkRaWEp1WkZWdFdIcDNkWGxLY25KclpIbGpTVFZoY2tkaFlUZHRiWFJQTmxKQlVpVXlSa2x2YXpkbVZFSTRXREp3T1VJM1JqUlZURTFtYldONVRTVXlSbVpHTVU1U0pUSkdUQ1V5UWpaUldIcFhVbGQxYm5STFlXYzRKVEpHWVhKTFExbHNiRzVGYm05SU16UnlhVEp0YzJaNWFGSlZRelJ6ZHpkM2NXSWxNa1l4VmxST00wSlljaVprYjNkdWJHOWhaRUZ6UFdsdWMzUmhiR3d1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR1ptbHNaWE11YzNSNWJHVnRlWE5sYkdZdWJtVjBKVEpHTjNvNU16Z3VaWGhs

http://www.citycleartower.com/c?x=qvl3M8TimyN3QX3wrPKHPBxnir6RJnk54vaWxgewarA=&e=0&c=DYMmXMP4xM1VMdxI8f7boLnCv5HHSIoPikvSazF/IgeObcTN5L9qwrH6JJ3B2dpPK/k73tMvdySBSRtv30e8O7p4p0/GL573AExLjlCAHBx4f2 H1vBghIw7yDlhzPl9 0hBgCYdBsli36o7KwmBPHaWHWlN5HD bx3s MMT1yg=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.citycleartower.com/c?x=Nz3V7QrVWs47s4mxFlZbY9WE0dptm3PklupbYVD M08=&e=0&c=ZeIkMrgr9gi73Wq7lV6wAezIjowuF804O4dVxCxVKgQECNK7gA1nRDHNY11gQH dxvLelyed6IKLSkAb94EsFBdmZDB3LUUWRZ29PjAODAyK43bVNKP2D RcoBYt84iMrnraD77R6 URZ/yqs4QZy7bAz3 rFVLlMjCpG9F6DpQ=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.citycleartower.com/c?x=XB7viiGoxYaxDOagQ6qJfaHKqkdjEJiy2Oj54zaSp10=&e=0&c=LHlOJ40h Rsh6iUTA7ygk4nLPcBC x/gEnYvk4fjv6CMCz9DHPf200yVyjReW4SbsAQpLKgjF c6l1/hBjTXSyjyiA4FmhWzfG1MIGxxkHb4SsHVH4ljbESn7ow0ppJhAW8bddFYGIyJ 2IzBv cMe3zlhAva23xNGBRZO5VGBY=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.citycleartower.com/c?x=5btG6L xwY2Tge9o4O3ZqHbCZ9IFGpZfXXu 3Zu7stI=&e=0&c=HQGVvvf 1Q63Bmt0iQzADuOgC6lio2XcmvS1v50N69KCgvJxxxgKH/rTYFMCHjl0Ef3MbkZEHqYOC5/qyKc hDCccWmJgNoLmYtWBPMc3yn6uYejCg85a8W6f SYsW1lWfnwHdH76CQOAWPPVfckuZrNN57LFrFLP43LImc9Jpo=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.citycleartower.com/c?x=YQ2vbOcE1wwgNoBiDquKZR/YTg6HJ9rjbycSJ I9rDo=&e=0&c=5bRMPyIEPDBW 5vLhJ4eGmc2WaZQkkJSs3urY4UTNX3ETNvgUPz12j98OW0fn11eb3LlB3pQIIah05SZu5 /pbNBsMjspk8k1i8l0WyWr OSkYugI8o4Ep5cAeEXS9Z mMzgAopXTiA87G1tV01JethYUgJRX5/SkmG1geQapAI=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.headsignscentral.com/WVl6OTRQVTg0YkRReFMwVkNOMDVDUzFWb0pUSkNNV2MxWTJ0YWRUQmpWV1JwTWxvME1HNWxUVEJTU0dKT2NrTXlZeVV6UkNaalBWQlhVVmxDVDFNNVMxQnRUMXBtTm5wS1ltZENialZFVldjelNGVmphVFYxVUZKd1VIbHRUMG96UzJoRU1FSjBSSFZQWlZkSlZGWktKVEpHUW5OeVN6WlNZbWhwVm5CR2VXOXlibWRITjFwTEpUSkNWRkZSTldzMVJucDVXSEF6VERoR2VEWm9ZWEV5TVVWclJqWTNXRVpPVDFwVlZFZHlhbGRqYmxOck5VWlNXbFpGVlNaa2IzZHViRzloWkVGelBXbHVjM1JoYkd3dVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdabWxzWlhNdVoyVnVhWFZ6TFhKdmRYUmxjaTVqYjIwbE1rWTNlamt6T0M1bGVHVT0=

http://www.citycleartower.com/c?x=c5GiGKaKWSe6Qy63s2wlrhCBWH4CutiMMPjnSSjlWWQ=&e=0&c=zkG3VqQ HrXmyoMk7J6Jef64mo8Le8Lp8chfBX5VPpUmwBeoNISFwsT4dJwR7rqUjcdSlAEW81wiPqPHWZ3iN36HdHn45o 8XjCd KYKM2x7QZq7F Fb/DhtaQrlf5zcaYED d5fuCQJHkTKTpg/fXaEPJOUX11weqXWkiQKlZQ=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.citycleartower.com/c?x=lBbHy5GqHkO1VHxhIWpHNnSonwmE1cPsHL M9TcKHMM=&e=0&c=XZDG56vwQeZwEtUGFvQYByXUQI0Rv37A3HGwJSDU9y21IP6CsdKMDnTS3V3RZMo2rxUTL3bDzcfoVdrm/P4 yOolRntBe6jbvaJ46QlUTgFmuj1LDYBUB0OQMK0WQOxZYiPVGgiVkI/rj3yJaANTY9QYEYe9nZ8HFSd32/xCPtc=&downloadAs=install.exe&fallback_url=http://.../7z938.exe

http://www.bundlecycledownload.com/WVl6OTRQVWROVUhoamMzVmhUVFZsWnpsWWJWUnFiMVpUSlRKR1EyNXFSV1phVDFObFdVZzNjVVJNTWtFbE1rSkhSRE5KSlRORUptTTlTalpoYzI1eVNXSWxNa1kxUWt0RFowb3phRWg1YzJoTFRsWjBiRFZNYlVGTWNXaHVTVzlMU0ZVek1HMVRRV001UzBkNVNrTWxNa0pVV1VkbWFXaHhaelUxVm5GeGNHSk1ZM2gwTUdNM1RVdGtNMVZRWkZwM1RFWlZaRkpWWldnNVMxaEZaRzVVVlVJbE1rSkdOVEZwZFhoVlZscGxRazVIZEZJelUxUmhNMlpCY0RoS2VsSW1aRzkzYm14dllXUkJjejFwYm5OMFlXeHNMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1acGJHVnpMbk4wZVd4bGJYbHpaV3htTG01bGRDVXlSamQ2T1RNNExtVjRaUT09

Latest 30 of 243 download URLs

Remove 7zip.exe - Powered by Reason Core Security