How 7-Zip Extracts Files from SFX Archives

Self-extracting (SFX) archives package compressed data alongside an executable module that unpacks the contents without requiring external software. However, running an untrusted executable file poses significant security risks. 7-Zip solves this problem by treating SFX .exe files as passive data containers rather than programs to be executed, parsing their binary layout to safely locate and extract the embedded files without executing any code.

The Structure of an SFX Archive

A typical Windows SFX archive is built using the Portable Executable (PE) file format. It consists of two primary components concatenated together:

  1. The SFX Stub: A standalone Windows executable containing the uncompressed logic required to decompress the payload and provide a user interface.
  2. The Archive Payload: The actual compressed data (such as a standard .7z or .zip stream), typically appended directly to the end of the executable stub or embedded within a resource section.

Header Parsing and Overlay Detection

When you open an SFX executable in 7-Zip, the software reads the file header instead of invoking the Windows loader. Windows PE files define specific section headers that state where the code, data, and resources end.

Any data appended after the last officially declared PE section is known as an "overlay." In most SFX configurations, the archive stream lives in this overlay region. 7-Zip reads the PE headers, calculates the defined size of the executable file, and identifies where the overlay begins.

Signature Scanning

If the archive is not appended as a clean overlay or if the PE structure has been modified, 7-Zip uses signature scanning.

7-Zip scans the binary content of the file for specific "magic bytes" that identify the beginning of supported archive formats. For instance, a 7z archive begins with the byte sequence 37 7A BC AF 27 1C (7z¼¯'). Once 7-Zip detects this signature inside the .exe, it marks the byte offset where the compressed data starts.

Extracting the Compressed Stream

Once the starting offset of the archive data is determined, 7-Zip feeds the remainder of the file into its standard decompression engine. The preceding executable stub is entirely ignored.

From this offset, 7-Zip processes the stream identically to a standalone .7z, .zip, or .rar file:

  • It reads the archive's internal header block to index file names, directory structures, timestamps, and attributes.
  • If encryption is enabled, it prompts for a password and decrypts the header and blocks.
  • It decompresses the data streams using the appropriate codec, such as LZMA or LZMA2, and writes the output files to disk.

By decoupling the data stream from the executable envelope, 7-Zip allows users to inspect and extract files from SFX archives on any platform—even non-Windows environments—without triggering the executable code.