Guide

Safe Download Practices

Most malware reaches users through downloads that look legitimate. This guide explains how to spot tampered installers, malicious mirrors, and fake download buttons — and how to verify what you downloaded.

The Most Common Attack: Fake Download Buttons

On many "download" pages, the largest, brightest button is an advertisement, not the real link. Clicking it leads to a redirect chain that ends in a bundled installer or a malicious executable.

Rule: the real download link usually comes from the same domain as the page. If the button leads to a third-party domain you do not recognize, treat it as suspicious.

Red Flags on a Download Page

  • Countdown timers before the download starts
  • Multiple stacked "Download" buttons of varying sizes
  • "Download will start in N seconds" messages
  • No file hash published anywhere
  • No file size shown
  • No version number
  • Pop-ups or new tabs opening on click
  • URLs that redirect through ad networks before reaching the file
  • The file has a double extension (for example, setup.pdf.exe)
  • The download is served over plain HTTP

How to Download Safely

  1. Identify the source. Use the official developer site or a trusted informational resource that links to it.
  2. Check the URL. Make sure you are on the domain you expect, with HTTPS.
  3. Look for the file hash. A serious publisher lists the SHA-256 hash, file size, and version.
  4. Download the file. Do not click any other button on the page.
  5. Verify the hash before running. See our verification guide.
  6. Check the file type. If you expected an .exe and got a .zip containing another .exe, treat it as suspicious.
  7. Scan the file. Upload it to VirusTotal or run it through your antivirus before executing.

What to Do After Downloading

  • Confirm the file size matches what was published.
  • Compute the SHA-256 hash and compare it to the published hash.
  • Check the digital signature (if one is expected).
  • Run the file with a standard user account first. Do not run as administrator unless the install requires it.
  • Watch for unexpected behavior during installation: new browser toolbars, changed homepage, installed extensions you did not request.

Mirrors and CDNs

Legitimate publishers often serve files from a CDN or mirror. This is normal. What matters is that the hash published by the primary source matches what the mirror served. If a mirror serves a different file, its hash will not match.

What "Unsigned" Means

A digital signature proves that a file was signed by a specific publisher and has not been modified since signing. Many tools — especially script executors and open-source utilities — are distributed unsigned. This is not itself a sign of malware, but it means the only integrity check available is the published SHA-256.

Reporting a Malicious Mirror

If you encounter a site impersonating SaveWave.lol, report it via our contact page. Include the URL and a screenshot if possible.

Related Guides

Verify SHA-256

Compute and compare a file hash on Windows.

Open →

Understanding SHA-256

How cryptographic hashes work.

Open →