I would keep it how you have it, but restrict the people who can download it to 100 posts here. have them pm you for the password for the rar file. If the pass is leeched, then just change it and it will stop all new people from getting it because the person who leeched it will have an old pass.
edit: or if you wanted you could set it up like gorfag did kinda and have a login system where you give people over 100 posts a unique user id to log in with. And keep record of who has what id so that if it is leeched you can track who leeched it.