I'm not really a windows guru; more of a unix guru; but as far as I can tell the signature of the program doesn't show up till after you run the setup; it seems applied to the binary that was wrapped in the setup.exe. Also you are right the md5 is not the best; though hardly weak given a known filesize; but sha256 is significantly more robust. Hum. Actually rumor is that md5 has been 'cracked'.
Anyways for those who wonder; to obtain the hash all you have to do is execute the following command (sha256sum Fallen...setup.exe)
or md5sum if you prefer the md5.