Essential storage keeps this site working and remembers your choice. Optional cookies are off until you allow them.

Meet the Synthient team

Loading available times…

Open Cal.com in a new tab

EARNFM

Provider

proxy provider intelligence profile

Website
earn[.]fm

EarnFM is a Swiss company operated by TeraShift GmbH whose exact launch date remains unverified. They are known for paid bandwidth sharing, the Fleetshare developer SDK, and a supplier program; their provider-size classification remains unverified. Synthient's Research Team did not verify a named downstream reseller. The corpus groups FleetSDK under Evomi, but that association does not establish that Evomi resells EarnFM or that the companies share ownership. Operator and consent policy · Fleetshare overview.

EarnFM is observed leveraging FleetSDK / Fleetshare to obtain IP addresses, with the SDK distributed across Android, Linux, Windows, and vendor-documented macOS. The FleetSDK / Fleetshare SDK is classified as Pay-Bandwidth / App Monetization and can be observed in the EarnFM app and Fleetshare host integrations. No additional third-party application is asserted without sample evidence.

Synthient's Research Team has not assigned a HIGH, MEDIUM, or LOW risk score to the reviewed FleetSDK corpus because no randomized sample of consent practices was completed. Current documentation requires recorded affirmative consent before bandwidth sharing and supports subsequent revocation. Those are published requirements, not an independent finding that every archived integration implements them correctly. Consent API.

Research record

Field
Operator / jurisdiction
Finding
TeraShift GmbH · Switzerland
Field
Operating history
Finding
Exact launch date and provider size remain unverified
Field
Network type
Finding
SDK-sourced pay-bandwidth and app-monetization network
Field
Verified channels
Finding
Fleetshare supplier program; Evomi corpus grouping is not treated as reseller or ownership proof
Field
SDK / platforms
Finding
FleetSDK / Fleetshare · Android, Linux, Windows, and vendor-documented macOS
Field
Consent / KYC
Finding
No consent-risk grade assigned and no randomized sample claimed; vendor documentation requires affirmative consent and revocation support; customer KYC not independently sampled
Field
Infrastructure
Finding
EarnFM app and Fleetshare host integrations are observed; related domains, certificates, hashes, and IPs appear below
Field
Review dates
Finding
Research updated 2026-09-28 · use the live lookup for current last-seen network observations

Reseller Graph

Observed provider, SDK, app, and reseller relationships described in this research profile.
Open full-size diagram

The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.


Yara Rules

rule Proxyware_FleetSDK_MultiPlatform_GoCore
{
    meta:
        description = "Fleet/Fleetshare Earn.fm Go core: websocket control plus reverse TCP/UDP task relay"
        provider    = "Evomi"
        sdk         = "FleetSDK"
        platform    = "Android/Linux ELF, Windows PE/DLL"
        variant     = "go-core"
        category    = "proxyware"
        author      = "Synthient"
        date        = "2026-08-27"
        confidence  = "high"
        intel_family = "fleet"
    strings:
        $go_package = "earnfm_sdk/fleetshareCore" ascii
        $src_tree   = "earnfm-go-sdk/fleetshareCore/" ascii
        $relay      = "wss://socket-prod.earn.fm:8443/ws" ascii
        $port_file  = "fleetshare_server_port_java.txt" ascii
        $hello      = "Hello from harvester" ascii
        $request    = "encryptedRequest" ascii
        $ffi        = "GetVersion_C called, returning" ascii
    condition:
        (uint32(0) == 0x464c457f or uint16(0) == 0x5a4d) and
        filesize > 256KB and filesize < 150MB and
        1 of ($go_package, $src_tree, $port_file, $ffi) and
        1 of ($relay, $hello, $request)
}

This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.

Indicators of Compromise

File Hashes

Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK
Type
SHA-256
Context
Confirmed files; FleetSDK

Domains

Type
Domain
Context
Tier 2; FleetSDK
Type
Domain
Context
Tier 2; FleetSDK
Type
Domain
Context
Backconnect Relays; FleetSDK
Type
Domain
Context
Backconnect Relays; FleetSDK
Type
Domain
Context
Backconnect Relays; FleetSDK
Type
Domain
Context
Backconnect Relays; FleetSDK
Type
Domain
Context
Backconnect Relays; FleetSDK

IP Addresses

Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK
Type
IP address
Context
Backconnect Relays; FleetSDK

Research updated September 28, 2026. Last-seen observations change continuously; verify an address with the live lookup before acting.

Additional IOCs are hidden.

Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.

7-day activity

Full access

Illustrative preview

See the activity behind the provider.

Unlock daily events and unique IP trends to understand how this provider’s network changes over time.

Compare plans