Live data from Hacker News

7zip.com Is Serving Malware

malwarebytes.com

51–60 of 104 posts

Re: 7zip.com Is Serving Malware

#51
post #50

[dead]

> Your machine runs a little slower, your bandwidth gets a little thinner, and someone halfway around the world is routing traffic through your home IP.

I wish in 2026 the default on new computers (Windows + Mac) was not only "inbound firewall on by default" but also outbound and users having to manually select what is allowed.

I know it is possible, it's just not the default and more of a "power user" thing at the moment. You have to know about it basically.

Re: 7zip.com Is Serving Malware

#52
post #46

I tested with the 3 major browsers and all 3 block it as "Suspected Phishing". So looks like the system is working as designed. Lookalike websites serving malware have always existed. So this isn't exactly news. But the browsers are blocking them like they should.

Weirdly, in Firefox 7zip.com is blocked but www.7zip.com isn't. If you type '7zip' in the address bar and then press Ctrl+Enter to go to the address, you'll get owned, because that key-combo adds the www at the beginning.

[deleted]

Re: 7zip.com Is Serving Malware

#53
post #16

Earlier quoted context omitted.

I migrated from 7-Zip to NanaZip, a fork with modern Windows features that the original developer refuses to implement. https://github.com/M2Team/NanaZip

Whenever I see "modern Windows experience", it always turns to be worse than the original one.

Well yeah, it says "modern" not "better".

Modern Windows and OS X and Android and iOS are all worse than the old ones.

Re: 7zip.com Is Serving Malware

#54
post #28

Earlier quoted context omitted.

> How can the average 7zip user know which one it is? I dunno, if you type "download 7zip" into Google, the top result is the official website. Also, 7zip.com is nowhere on the first page, and the most common browsers show you explicitly it's a phishing website. This is actually a pretty good case of the regular user being pretty safe from downloading malware.

> I dunno, if you type "download 7zip" into Google, the top result is the official website. Until someone puts an ad above it.

Sure, but the answer to "How can the average 7zip user know which one it is?" would then be "do a Google search and use uBlock Origin".

Re: 7zip.com Is Serving Malware

#56
post #16

Earlier quoted context omitted.

I migrated from 7-Zip to NanaZip, a fork with modern Windows features that the original developer refuses to implement. https://github.com/M2Team/NanaZip

Whenever I see "modern Windows experience", it always turns to be worse than the original one.

I take your point, and usually you're right, but in this case "modern features" includes things like having an "extract" button show up when you right click an archive file in Explorer.

Re: 7zip.com Is Serving Malware

#57
post #41
post #15

Earlier quoted context omitted.

How can the average 7zip user know which one it is? Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page. What are the other mechanisms for finding out the official website of a software?

Open source software will have a code repo with active development happening on it. That repo will usually link to official Web page and download places.

Not universal true. Open source just means that the code is avaiable, not that developement happens in the open. (But 7zip does have a github repo)

Re: 7zip.com Is Serving Malware

#58
post #50

[dead]

> Your machine runs a little slower, your bandwidth gets a little thinner, and someone halfway around the world is routing traffic through your home IP. I wish in 2026 the default on new computers (Windows + Mac) was not only "inbound firewall on by default" but also outbound and users having to manually select what is allowed. I know it is possible, it's just not the default and more of a "power user" thing at the m…

As a power user I agree, but how do you avoid it being like the Vista UAC popups? Everyone expects software to auto update these days and it's easy enough to social engineer someone into accepting.

Re: 7zip.com Is Serving Malware

#59
post #50

[dead]

> Your machine runs a little slower, your bandwidth gets a little thinner, and someone halfway around the world is routing traffic through your home IP. I wish in 2026 the default on new computers (Windows + Mac) was not only "inbound firewall on by default" but also outbound and users having to manually select what is allowed. I know it is possible, it's just not the default and more of a "power user" thing at the m…

Even if it was a default there is so many services reaching out the non-technical user would get assaulted with requests from services which they have no idea about. Eventually people will just click ok with out reading anything which puts you back at square one with annoying friction.

Re: 7zip.com Is Serving Malware

#60
post #32

Earlier quoted context omitted.

> How can the average 7zip user know which one it is? I dunno, if you type "download 7zip" into Google, the top result is the official website. Also, 7zip.com is nowhere on the first page, and the most common browsers show you explicitly it's a phishing website. This is actually a pretty good case of the regular user being pretty safe from downloading malware.

I feel I need to clarify my earlier comment. I was asking how can a user tell, in general, what is the legitimate website of a software, not just how to know what 7zip.com is malicious. Are the search removals and phishing warnings reactive or proactive? Because if it is the former then we don't really know how many users are already affected before security researchers got notified and took action. Also, 7zip is not…

One way is to consult the same source(s) where the user learned about the software in the first place.
Post reply on HN