Safe Download Practices
Most malware reaches users through downloads that look legitimate. This guide explains how to spot tampered installers, malicious mirrors, and fake download buttons — and how to verify what you downloaded.
The Most Common Attack: Fake Download Buttons
On many "download" pages, the largest, brightest button is an advertisement, not the real link. Clicking it leads to a redirect chain that ends in a bundled installer or a malicious executable.
Rule: the real download link usually comes from the same domain as the page. If the button leads to a third-party domain you do not recognize, treat it as suspicious.
Red Flags on a Download Page
- Countdown timers before the download starts
- Multiple stacked "Download" buttons of varying sizes
- "Download will start in N seconds" messages
- No file hash published anywhere
- No file size shown
- No version number
- Pop-ups or new tabs opening on click
- URLs that redirect through ad networks before reaching the file
- The file has a double extension (for example,
setup.pdf.exe) - The download is served over plain HTTP
How to Download Safely
- Identify the source. Use the official developer site or a trusted informational resource that links to it.
- Check the URL. Make sure you are on the domain you expect, with HTTPS.
- Look for the file hash. A serious publisher lists the SHA-256 hash, file size, and version.
- Download the file. Do not click any other button on the page.
- Verify the hash before running. See our verification guide.
- Check the file type. If you expected an .exe and got a .zip containing another .exe, treat it as suspicious.
- Scan the file. Upload it to VirusTotal or run it through your antivirus before executing.
What to Do After Downloading
- Confirm the file size matches what was published.
- Compute the SHA-256 hash and compare it to the published hash.
- Check the digital signature (if one is expected).
- Run the file with a standard user account first. Do not run as administrator unless the install requires it.
- Watch for unexpected behavior during installation: new browser toolbars, changed homepage, installed extensions you did not request.
Mirrors and CDNs
Legitimate publishers often serve files from a CDN or mirror. This is normal. What matters is that the hash published by the primary source matches what the mirror served. If a mirror serves a different file, its hash will not match.
What "Unsigned" Means
A digital signature proves that a file was signed by a specific publisher and has not been modified since signing. Many tools — especially script executors and open-source utilities — are distributed unsigned. This is not itself a sign of malware, but it means the only integrity check available is the published SHA-256.
Reporting a Malicious Mirror
If you encounter a site impersonating SaveWave.lol, report it via our contact page. Include the URL and a screenshot if possible.