I compared https://7-zip.org/a/7z2600-x64.exe with https://7-zip.com/a/7z2600-x64.exe. They are byte-for-byte identical. If there's malware, it isn't obvious.
The OP refers to 7zip.com, no dash. Those dashed domains directly resolve to the same Hetzner server, but the undashed one heads off into Cloudflare.
Seems this all comes down to the wrong domain (.org vs .com).
The OP refers to 7zip.com, no dash. Those dashed domains directly resolve to the same Hetzner server, but the undashed one heads off into Cloudflare.