>>12
But if the hash you have in your local database doesn't match the one from the package you downloaded, then it is clear that it has been tampered with. It doesn't matter where you downloaded it from, if it's no different to that which you had expected, then there is nothing wrong with it.