OriginGuard
Distribution Integrity Report
System Informer
- Product
- System Informer
- Authoritative project
- winsiderss/systeminformer
- Research observation
- 07 September 2026
- Review mode
- Manual public-source research
Key conclusion
No high-priority security alert warranted from the evidence reviewed.
One older distribution origin remains unresolved. It is recorded as unverified stale distribution origin, not malicious, compromised, impersonating, or unauthorized.
01 · Executive summary
The review found a distribution question, not a proven incident.
What was established
- • The authoritative project is
winsiderss/systeminformer. - • The observed release family was 4.0.26241.138 / 4.0.26241.
- • Official release and website distribution evidence aligned for the research observation.
- • No modified artifact, malware evidence, or high-priority impersonation finding was established.
What remains unresolved
The older system-informer.app page offered genuine historical GitHub artifacts, but the available first-party evidence did not establish that the domain was owned or authorised by the project. That is an evidence gap, not proof of wrongdoing.
02 · Publisher truth
Start from the project’s own distribution truth.
- Authoritative project
- winsiderss/systeminformer
- Canonical project website
- systeminformer.com
- Current release family observed
- 4.0.26241.138 / 4.0.26241
First-party association
Multiple domains appear connected to legitimate project infrastructure. The evidence is not identical for each domain, so the classifications below preserve that difference instead of turning association into a blanket ownership claim.
03 · Current release integrity
The release evidence supported suppression of the apparent alert.
Release family and artifact evidence
The official GitHub release identifies v4.0.26241.138. During the research observation, the official release artifacts had SHA-256 values matching the current systeminformer.com distribution for the observed release family. The official downloads page publishes the following values for the setup and portable artifacts:
Setup SHA-256
CEB46BC42CD9993A3A8E9E7002D1F1715E3D2A077D5226D72612E2B8578E51EB
Portable binaries SHA-256
3E12CC4F1FFA1CC34AB9202A9DFE410724CB8B68AAF2EFA43C01D3705B27219E
This is a public-source comparison at the stated observation time. OriginGuard did not execute the binaries and does not present this as malware analysis.
04 · Observed distribution origins
Every origin gets a classification and an action.
The table is intentionally conservative. An unfamiliar origin can remain unresolved without becoming a security accusation.
winsiderss/systeminformer
OFFICIAL- Observed role
- Authoritative project
- Evidence
- The public source repository identifies the project and links the maintained System Informer distribution ecosystem.
- Action
- Use as the publisher truth anchor.
systeminformer.com
OFFICIAL / FIRST-PARTY- Observed role
- Canonical project website
- Evidence
- The official downloads page links release artifacts, package channels, and published SHA-256 values.
- Action
- Use as the canonical distribution reference.
system-informer.com
AUTHORIZED- Observed role
- Related project domain
- Evidence
- In the official repository discussion, maintainer jxy-s states that the project owns and operates both systeminformer.com and system-informer.com. This source supports this domain pair only; it does not generalise that proof to .io, .dev, .app, or every similarly named domain.
- Action
- Treat as related infrastructure; retain the source boundary.
systeminformer.io
AUTHORIZED- Observed role
- Security and distribution infrastructure
- Evidence
- The official project security documentation publishes a security contact at this domain; the official project links also reference it.
- Action
- Treat as strong first-party association, not a universal ownership claim.
systeminformer.dev
AUTHORIZED- Observed role
- Release/update infrastructure
- Evidence
- The official project distribution links expose a matching release-family download surface and update infrastructure.
- Action
- Treat as strong project infrastructure association.
system-informer.app
UNVERIFIED STALE DISTRIBUTION ORIGIN- Observed role
- Observed older download page
- Evidence
- The page presented an older System Informer release and links to genuine historical artifacts in the authoritative GitHub repository. Ownership or authorization by the project was not established from available first-party evidence.
- Action
- Keep visible for manual follow-up; do not escalate on this evidence alone.
05 · Finding detail
system-informer.app
UNVERIFIED STALE DISTRIBUTION ORIGIN
No escalationThe page presented an older System Informer release. Its download links pointed to genuine historical artifacts in the official WinsiderSS GitHub repository, but ownership or authorization by the project was not established from the available first-party evidence. No modified artifact and no malware evidence were established.
Initial observation
An unfamiliar domain presented an older release and looked like a possible distribution divergence.
Deeper evidence
The linked artifacts were genuine historical project artifacts; the domain relationship itself remained unverified.
Final action
NO HIGH-PRIORITY ALERT
Keep the gap visible for follow-up.
06 · Suppressed alert example
The value was in separating a stale page from a proven attack.
Initial observation
Version and domain divergence looked suspicious enough to investigate.
Deeper evidence
First-party infrastructure and matching current release evidence explained the legitimate distribution ecosystem; the older page still lacked established authorization.
Final action
NO HIGH-PRIORITY ALERT
07 · Evidence limitations
What this report does not prove.
- • This is point-in-time public-source research.
- • Ownership relationships may change.
- • Public evidence can be stale.
- • Absence of evidence is not proof of unauthorized activity.
- • Malware analysis was not performed.
- • OriginGuard did not execute suspicious binaries.
08 · Final classification summary
A clear close, including the unknowns.
Official / first-party
winsiderss/systeminformer
systeminformer.com
Unverified
system-informer.app
High priority
None established
Sources reviewed
First-party links used for the publisher truth.
Sample / demonstration only. No customer engagement, continuous monitoring, legal conclusion, takedown capability, or malware verdict is represented by this page.