Why fakes exist at all
MAS is open source and plain text. Copying it takes seconds, and adding a few lines that fetch a payload takes seconds more. Because the project is popular, the search results for massgrave.dev and related terms are a profitable place to park a clone.
The good news: the fakes share a small set of tells, and you only need to check four things.
1. What file type are you being offered?
Genuine MAS is a batch script or a plain archive containing batch and PowerShell files. If the download is:
- an
.exe - an "installer" or "download manager"
- an
.msi - a password-protected archive whose password appears in a YouTube description
…then it is not the project. No exceptions.
2. Can you read it?
Open MAS_AIO.cmd in Notepad. Every command is human-readable. Scan for lines that download binaries from hosts you do not recognise, or long base64 blobs piped into PowerShell. Genuine MAS does not need either.
3. Does the hash match?
Get-FileHash .\\MAS_AIO.cmd -Algorithm SHA256
Compare against the hash published with the release. Mismatch means altered — stop there.
4. Which detection is your antivirus reporting?
HackTool:Win32/AutoKMS is expected: it classifies activation tooling by purpose, and it fires on legitimate enterprise KMS utilities too. A Trojan, Stealer, Miner or Banker family name is not expected and means you have a repackage.
The safest route bypasses the question
irm https://get.activated.win | iex
This fetches the current release straight into memory in an elevated terminal. There is no archive to be swapped, no host to be spoofed in the middle of an extraction, and nothing left behind if you close the window.
About mirrors
Legitimate mirrors exist — code hosts, archives, and community rehosts — and they are useful when a network blocks the primary domain. Treat a mirror as genuine only after the hash matches. A mirror that ships a different file type than the original is not a mirror, it is a clone.
If you already ran something suspicious
Disconnect from the network, run a full offline scan with Defender, check Task Scheduler for unfamiliar tasks, check Autoruns for new startup entries, and change passwords for anything you signed into afterwards. Then re-activate from a source you verified.
Get the script
Open Terminal (Admin) or PowerShell (Admin) and run:
irm https://get.activated.win | iex
Prefer offline? Grab the archive from the download page and run MAS_AIO.cmd as administrator. More help: MAS script overview · Massgrave Windows guide · troubleshooting · error decoder.