Avoid random file-hosting sites unless the file is cryptographically signed or matches community-known hashes.