← Back to all posts

How to Check If a Downloaded File Is Safe Before Opening It

To check a downloaded file before opening it, verify the source, inspect the filename and type, scan it with your security software, and investigate any unexplained findings. For software downloads, compare a published checksum when the developer provides one. No single check guarantees safety.

Blue Lantern Security can add static file analysis to that process: it inspects a file without executing it and shows findings you can review. Start with the source, though. A clean scan cannot explain why an unexpected download appeared in the first place.

1. Confirm you meant to download this file

Ask what you were trying to obtain and who should have supplied it. If you wanted a printer driver, find the manufacturer's support page independently. If a website prompted an unexpected browser update, use the browser's own update mechanism instead of the downloaded installer.

For a file sent by another person, confirm the request through an existing contact method. A familiar name or an ongoing email thread is useful context, but it is not sufficient evidence on its own.

Keep any browser or operating-system warning in place while you investigate. Chrome distinguishes dangerous, suspicious, unverified, and insecure downloads; those labels do not all mean the same thing. Its download-warning guidance explains the differences. A warning is a reason to check, not an instruction to disable protection.

2. Look at the file's full name and type

Use your file manager's details or properties without launching the file. Make sure the full extension is visible. A name such as invoice.pdf.exe ends in .exe; the earlier .pdf text does not make it a PDF.

Then compare the type with what you expected. An installer may legitimately be an executable. An invoice normally should not require running one.

What you notice What to check next
A document name ending in an executable or script extension Verify the sender and have the file examined before running it
An archive such as a ZIP Find out why it was sent; checking the container is not evidence that every file inside was inspected
A PDF or Office document Check the source and scan it; an ordinary document format proves nothing about the sender
A missing or unexpected extension Ask for an explanation and compare it with the detected format in a file-analysis report
Instructions to disable antivirus or run a copied command Stop and verify the request independently; this is the pattern behind ClickFix-style attacks

A filename is only a label. Blue Lantern Security's file-type check compares that label with information inside the file, which can reveal a mismatch. A matching type is useful identification, not a safety verdict.

3. Scan the file with your device's security software

Keep your security software updated and use its option to scan the specific file. Do not double-click the download to see whether your antivirus reacts.

On Windows, right-click the file, choose Show more options if needed, and select Scan with Microsoft Defender. If another security product is active, use that product's scanning workflow. Microsoft's file-scanning instructions explain the available controls.

On a Mac, the built-in XProtect and Gatekeeper protections check an app when you first open it, as Apple's platform security guide describes. They do not offer an on-demand scan of a closed file. If you run third-party security software on a Mac, use its scan option; otherwise, rely on the hosted check in step 4 and the checksum in step 5.

Read the result and follow the security product's guidance if it finds a threat. Do not restore a quarantined file simply because its download page says detections are false positives.

4. Add a file check if uncertainty remains

If uploading is allowed, submit the file to Blue Lantern Security's Static Malware Analyzer. It checks contents and structure without executing the file.

The web app accepts files up to 4.5 MB and requires an account. Personal accounts include 30 free daily runs shared across the file, email, and URL analyzers. Choose the checks you want or use Run All Checks, then review the completed report in the Monitoring Hub.

Look for the evidence that addresses your concern. Did a supposed document have a different detected type? Which malware rules matched? Is an unusual file region consistent with normal compression, or does it appear alongside other suspicious findings?

Before submitting a confidential document, check your organization's upload rules. Blue Lantern Security processes the file on its infrastructure. Its privacy policy sets a maximum one-day retention for uploaded files and a one-week lifetime for reports; metadata about each run is retained indefinitely.

For files above the upload limit, use an approved tool that supports the complete file. Trimming or splitting a file can change what an analyzer sees.

5. For software, compare the publisher's checksum

A checksum is a fingerprint calculated from file contents. If a software publisher supplies a SHA-256 checksum on its official release page, compare it with the checksum of your download. A mismatch means you do not have the expected bytes; check the version and source before proceeding.

On Windows, PowerShell can calculate one without executing the target file:

Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\installer.exe' -Algorithm SHA256

On a Mac, Terminal can do the same:

shasum -a 256 ~/Downloads/installer.dmg

Replace the path with the location of your download. Microsoft documents the Get-FileHash command. You do not need this step for every attachment, and you should not run commands supplied by a suspicious download page.

A matching checksum shows that the bytes match the reference. It does not show that the software is harmless. The reference must come from the publisher you intended to trust. Comparing against a checksum supplied by the same suspicious sender adds little confidence.

Can I check a file without uploading it?

Yes. Local security software can inspect it, and a checksum can help verify a software download. You can also search for an existing report by hash through a service such as VirusTotal. That lookup sends the hash rather than a new copy of the file, but only returns information already available for it. The file-scanner comparison explains that distinction and the services' submission privacy.

If no report exists, the file is unknown to that lookup. It has not passed a scan.

When should I leave the file closed?

Leave it closed when its origin, type, or findings do not make sense, or when you are being asked to bypass a security control. For work files, share the message and findings through your normal security-reporting process.

An expected download from a verified publisher with consistent file details and no detected issues gives you more reason to trust it. It still does not remove the need for current software, endpoint protection, and ordinary access controls.

For the next step, see how to interpret a malware scan result. If the download came from an email, also follow the attachment-checking guide, because the message can expose a problem that the file alone does not.

Check a suspicious file with Blue Lantern Security