This reminds me of drivers sites where right next to the actual download link (in a very discrete font and size) there are ads that have big "DOWNLOAD NOW" buttons that aren't the actual download buttons for the driver but are just links to malware, etc.
Seems so many sites do that now, pisses me right off.
Even seen open source software sites do this. It's really sad to see people resort to that. I guess the CTR is probably high on those.
Whenever I download something I always question if what I'm about to click is actually the real download button. I noticed most of the time they don't have an image, and it's just a tiny link at the bottom, so basically go for the smallest one, and hover the url to make sure it's not some ad server. But if you're in a hurry it's easy to accidentally click the wrong one.