Loading Vauntico...

OriginGuard

Distribution Integrity Report

System Informer

Sample / DemonstrationPoint-in-time review
Product
System Informer
Authoritative project
winsiderss/systeminformer
Research observation
07 September 2026
Review mode
Manual public-source research

Key conclusion

No high-priority security alert warranted from the evidence reviewed.

One older distribution origin remains unresolved. It is recorded as unverified stale distribution origin, not malicious, compromised, impersonating, or unauthorized.

01 · Executive summary

The review found a distribution question, not a proven incident.

What was established

  • • The authoritative project is winsiderss/systeminformer.
  • • The observed release family was 4.0.26241.138 / 4.0.26241.
  • • Official release and website distribution evidence aligned for the research observation.
  • • No modified artifact, malware evidence, or high-priority impersonation finding was established.

What remains unresolved

The older system-informer.app page offered genuine historical GitHub artifacts, but the available first-party evidence did not establish that the domain was owned or authorised by the project. That is an evidence gap, not proof of wrongdoing.

02 · Publisher truth

Start from the project’s own distribution truth.

Authoritative project
winsiderss/systeminformer
Canonical project website
systeminformer.com
Current release family observed
4.0.26241.138 / 4.0.26241

First-party association

Multiple domains appear connected to legitimate project infrastructure. The evidence is not identical for each domain, so the classifications below preserve that difference instead of turning association into a blanket ownership claim.

03 · Current release integrity

The release evidence supported suppression of the apparent alert.

Release family and artifact evidence

The official GitHub release identifies v4.0.26241.138. During the research observation, the official release artifacts had SHA-256 values matching the current systeminformer.com distribution for the observed release family. The official downloads page publishes the following values for the setup and portable artifacts:

Evidence aligned

Setup SHA-256

CEB46BC42CD9993A3A8E9E7002D1F1715E3D2A077D5226D72612E2B8578E51EB

Portable binaries SHA-256

3E12CC4F1FFA1CC34AB9202A9DFE410724CB8B68AAF2EFA43C01D3705B27219E

This is a public-source comparison at the stated observation time. OriginGuard did not execute the binaries and does not present this as malware analysis.

04 · Observed distribution origins

Every origin gets a classification and an action.

The table is intentionally conservative. An unfamiliar origin can remain unresolved without becoming a security accusation.

winsiderss/systeminformer

OFFICIAL
Observed role
Authoritative project
Evidence
The public source repository identifies the project and links the maintained System Informer distribution ecosystem.
Action
Use as the publisher truth anchor.

systeminformer.com

OFFICIAL / FIRST-PARTY
Observed role
Canonical project website
Evidence
The official downloads page links release artifacts, package channels, and published SHA-256 values.
Action
Use as the canonical distribution reference.

system-informer.com

AUTHORIZED
Observed role
Related project domain
Evidence
In the official repository discussion, maintainer jxy-s states that the project owns and operates both systeminformer.com and system-informer.com. This source supports this domain pair only; it does not generalise that proof to .io, .dev, .app, or every similarly named domain.
Action
Treat as related infrastructure; retain the source boundary.

systeminformer.io

AUTHORIZED
Observed role
Security and distribution infrastructure
Evidence
The official project security documentation publishes a security contact at this domain; the official project links also reference it.
Action
Treat as strong first-party association, not a universal ownership claim.

systeminformer.dev

AUTHORIZED
Observed role
Release/update infrastructure
Evidence
The official project distribution links expose a matching release-family download surface and update infrastructure.
Action
Treat as strong project infrastructure association.

system-informer.app

UNVERIFIED STALE DISTRIBUTION ORIGIN
Observed role
Observed older download page
Evidence
The page presented an older System Informer release and links to genuine historical artifacts in the authoritative GitHub repository. Ownership or authorization by the project was not established from available first-party evidence.
Action
Keep visible for manual follow-up; do not escalate on this evidence alone.

05 · Finding detail

system-informer.app

UNVERIFIED STALE DISTRIBUTION ORIGIN

No escalation

The page presented an older System Informer release. Its download links pointed to genuine historical artifacts in the official WinsiderSS GitHub repository, but ownership or authorization by the project was not established from the available first-party evidence. No modified artifact and no malware evidence were established.

Initial observation

An unfamiliar domain presented an older release and looked like a possible distribution divergence.

Deeper evidence

The linked artifacts were genuine historical project artifacts; the domain relationship itself remained unverified.

Final action

NO HIGH-PRIORITY ALERT

Keep the gap visible for follow-up.

06 · Suppressed alert example

The value was in separating a stale page from a proven attack.

Initial observation

Version and domain divergence looked suspicious enough to investigate.

Deeper evidence

First-party infrastructure and matching current release evidence explained the legitimate distribution ecosystem; the older page still lacked established authorization.

Final action

NO HIGH-PRIORITY ALERT

07 · Evidence limitations

What this report does not prove.

  • • This is point-in-time public-source research.
  • • Ownership relationships may change.
  • • Public evidence can be stale.
  • • Absence of evidence is not proof of unauthorized activity.
  • • Malware analysis was not performed.
  • • OriginGuard did not execute suspicious binaries.

08 · Final classification summary

A clear close, including the unknowns.

Official / first-party

winsiderss/systeminformer
systeminformer.com

Unverified

system-informer.app

High priority

None established

Sources reviewed

First-party links used for the publisher truth.

Sample / demonstration only. No customer engagement, continuous monitoring, legal conclusion, takedown capability, or malware verdict is represented by this page.