You can probably be sure that Omer's link is trustworthy if it produces the same checksum hash that is expected, because finding a malicious file that does what an attacker wants, while at the same time producing the same hash as the legit file is so computationally intensive (like near impossible), that a random Mineacraftian having such capability would be almost as likely as a unicorn.
Whilst SHA-1 is not secure for other functions, such as password storage, it's perfectly secure for file integrity checks.