I'm pretty sure an HTTPS GET request to http[s]://iweb.dl.sourceforge.net/project/handbrake/0.10.0/HandBrake-0.10.0-MacOSX.6_GUI_x86_64.dmg would be pretty easy to identify as a HandBrake download. The resource requested is not hidden.
Your GET request, and the server's reply, is encrypted.
The hostname of your request might leak in SNI, or if your DNS lookup was insecure.
It is also plausible that an eavesdropper could make a solid guess as to what you downloaded by counting bytes, but that's obviously not worth much.
You don't need a DNS leak; if you aren't using SNI, the server(s) replying on that IP can only serve a single cert, so the snooper can usually find out the hostname by simply connecting to it and seeing what it gets.
The exception is if the site is behind something like Cloudflare, which stuff dozens or hundreds of hostnames in a single cert.