Live data from Hacker News

7zip.com Is Serving Malware

malwarebytes.com

61–70 of 104 posts

Re: 7zip.com Is Serving Malware

#61
post #39

I've started using winget to install my apps for exactly this reason. I can't keep track of every url for every piece of software.

Is that safe? Microsoft's policy [1] seems to say that anyone can publish an update to a package as long as it passes "an automated process" which checks that it's "not known to be malicious".

[1] https://learn.microsoft.com/en-us/windows/package-manager/pa...

Re: 7zip.com Is Serving Malware

#62
post #28

Earlier quoted context omitted.

> I dunno, if you type "download 7zip" into Google, the top result is the official website. Until someone puts an ad above it.

Sure, but the answer to "How can the average 7zip user know which one it is?" would then be "do a Google search and use uBlock Origin".

How does the user know they are using the official uBlock Origin?

Re: 7zip.com Is Serving Malware

#63
post #50

[dead]

> Your machine runs a little slower, your bandwidth gets a little thinner, and someone halfway around the world is routing traffic through your home IP. I wish in 2026 the default on new computers (Windows + Mac) was not only "inbound firewall on by default" but also outbound and users having to manually select what is allowed. I know it is possible, it's just not the default and more of a "power user" thing at the m…

I use LuLu (https://objective-see.org/products/lulu.html) to block outgoing connections and manually select which connections/apps are allowed. It's free and works just fine.

Re: 7zip.com Is Serving Malware

#64

Earlier quoted context omitted.

Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC. But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.

Like I said, theres a LOT of open source projects that show that prompt. Signing an MSI involves having a valid CA certificate, which AFAIK is not free, and goes beyond the budget of most projects.

We're up for renewal with PortableApps.com. The same one year non-EV code signing certificate with a USB token that was US$246 last year is now US$434 from GlobalSign. The lower prices you see some places are for 2+ years.

Note that the certificate itself is only for 1 year regardless of how long you buy one for and you need to go through the renewal process each year just without payment.

Re: 7zip.com Is Serving Malware

#65
post #15

Earlier quoted context omitted.

How can the average 7zip user know which one it is? Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page. What are the other mechanisms for finding out the official website of a software?

> How can the average 7zip user know which one it is? I dunno, if you type "download 7zip" into Google, the top result is the official website. Also, 7zip.com is nowhere on the first page, and the most common browsers show you explicitly it's a phishing website. This is actually a pretty good case of the regular user being pretty safe from downloading malware.

> Also, 7zip.com is nowhere on the first page

In incognito window, for me, it's 3rd result

Re: 7zip.com Is Serving Malware

#66
post #16

Does the 7-Zip author still refuse to digitally sign or even provide hashes of the official downloads? It's an extremely weird flex, he thinks it's a frivolous waste of time or something.

I migrated from 7-Zip to NanaZip, a fork with modern Windows features that the original developer refuses to implement. https://github.com/M2Team/NanaZip

Windows 11 has 7-zip support built in.

Re: 7zip.com Is Serving Malware

#67
post #50

[dead]

> Your machine runs a little slower, your bandwidth gets a little thinner, and someone halfway around the world is routing traffic through your home IP. I wish in 2026 the default on new computers (Windows + Mac) was not only "inbound firewall on by default" but also outbound and users having to manually select what is allowed. I know it is possible, it's just not the default and more of a "power user" thing at the m…

Fort Firewall for the win.

https://github.com/tnodir/fort

Re: 7zip.com Is Serving Malware

#68
post #62

Earlier quoted context omitted.

Sure, but the answer to "How can the average 7zip user know which one it is?" would then be "do a Google search and use uBlock Origin".

How does the user know they are using the official uBlock Origin?

The Mozilla extension store doesn't have ads, so it's the top item. It has clear download counts and a "recommended" icon.

So the advice is to install it from the extension store.

Re: 7zip.com Is Serving Malware

#69
post #50

[dead]

> It's a fundamentally different threat model and most endpoint protection isn't looking for it because the behavioral signatures look like normal network activity.

Is it even possible for a prosumer home router like OPNsense or OpenWRT to detect this?

Re: 7zip.com Is Serving Malware

#70
The .com site serving malware aside, it's how people even get to downloading this. PC builder [...], USB stick [...], YouTube tutorial for a new build [...] instructed to download. Makes me wonder, is this how "PC builders" build PCs, or was this a regular user person. Archive managers are such basic software that I'd think surely someone would keep a stash of (trusted) installer files for the basic tools to be installed in a new environment. At least that's what we used to do, like, 25 years ago. Or use choco, winget or whatever. Malware hygiene habits remain almost unchanged - don't click that link.
Post reply on HN