The Application Firewall feature can be used to block the download of .exe files. This article shows the steps to configure it.
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Create Match Object:
Select input type representation as hexadecimal and add the following patterns into the object (or you can add these to a file by selecting Import option, so you do not have to type them in manually) and click on Save

Create App Rule:

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Create Match Object:
Create the Match Object of type Custom. Using input type hexadecimal, add the following patterns into the object (or you can add these to a file which you can use with the Load from File option, so you do not have to type them in manually) and click on OK to Save

Create App Rule:

When an HTTP download of an EXE file is blocked by the configured Application Firewall policy, you will see a log message like this:
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
Create the Match Object of type Custom. Using input type hexadecimal, add the following patterns into the object (or you can add these to a file which you can use with the Load from File option, so you do not have to type them in manually) and click OK

Create App Control Policy of type HTTP Server and use the above created object in this Application policy. Use Reset/Drop action if you want to block these or No Action if you want to just log them. Set direction of the policy as ‘incoming’ and save the policy:

When an HTTP download of an EXE file is blocked by the configured Application Firewall policy, you will see a log message like this: