EARNFM
Providerproxy provider intelligence profile
- Website
earn[.]fm
EarnFM is a Swiss company operated by TeraShift GmbH whose exact launch date remains unverified. They are known for paid bandwidth sharing, the Fleetshare developer SDK, and a supplier program; their provider-size classification remains unverified. Synthient's Research Team did not verify a named downstream reseller. The corpus groups FleetSDK under Evomi, but that association does not establish that Evomi resells EarnFM or that the companies share ownership. Operator and consent policy · Fleetshare overview.
EarnFM is observed leveraging FleetSDK / Fleetshare to obtain IP addresses, with the SDK distributed across Android, Linux, Windows, and vendor-documented macOS. The FleetSDK / Fleetshare SDK is classified as Pay-Bandwidth / App Monetization and can be observed in the EarnFM app and Fleetshare host integrations. No additional third-party application is asserted without sample evidence.
Synthient's Research Team has not assigned a HIGH, MEDIUM, or LOW risk score to the reviewed FleetSDK corpus because no randomized sample of consent practices was completed. Current documentation requires recorded affirmative consent before bandwidth sharing and supports subsequent revocation. Those are published requirements, not an independent finding that every archived integration implements them correctly. Consent API.
Research record
| Field | Finding |
|---|---|
| Operator / jurisdiction | TeraShift GmbH · Switzerland |
| Operating history | Exact launch date and provider size remain unverified |
| Network type | SDK-sourced pay-bandwidth and app-monetization network |
| Verified channels | Fleetshare supplier program; Evomi corpus grouping is not treated as reseller or ownership proof |
| SDK / platforms | FleetSDK / Fleetshare · Android, Linux, Windows, and vendor-documented macOS |
| Consent / KYC | No consent-risk grade assigned and no randomized sample claimed; vendor documentation requires affirmative consent and revocation support; customer KYC not independently sampled |
| Infrastructure | EarnFM app and Fleetshare host integrations are observed; related domains, certificates, hashes, and IPs appear below |
| Review dates | Research updated 2026-09-28 · use the live lookup for current last-seen network observations |
- Field
- Operator / jurisdiction
- Finding
- TeraShift GmbH · Switzerland
- Field
- Operating history
- Finding
- Exact launch date and provider size remain unverified
- Field
- Network type
- Finding
- SDK-sourced pay-bandwidth and app-monetization network
- Field
- Verified channels
- Finding
- Fleetshare supplier program; Evomi corpus grouping is not treated as reseller or ownership proof
- Field
- SDK / platforms
- Finding
- FleetSDK / Fleetshare · Android, Linux, Windows, and vendor-documented macOS
- Field
- Consent / KYC
- Finding
- No consent-risk grade assigned and no randomized sample claimed; vendor documentation requires affirmative consent and revocation support; customer KYC not independently sampled
- Field
- Infrastructure
- Finding
- EarnFM app and Fleetshare host integrations are observed; related domains, certificates, hashes, and IPs appear below
- Field
- Review dates
- Finding
- Research updated 2026-09-28 · use the live lookup for current last-seen network observations
Reseller Graph
The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.
Yara Rules
rule Proxyware_FleetSDK_MultiPlatform_GoCore
{
meta:
description = "Fleet/Fleetshare Earn.fm Go core: websocket control plus reverse TCP/UDP task relay"
provider = "Evomi"
sdk = "FleetSDK"
platform = "Android/Linux ELF, Windows PE/DLL"
variant = "go-core"
category = "proxyware"
author = "Synthient"
date = "2026-08-27"
confidence = "high"
intel_family = "fleet"
strings:
$go_package = "earnfm_sdk/fleetshareCore" ascii
$src_tree = "earnfm-go-sdk/fleetshareCore/" ascii
$relay = "wss://socket-prod.earn.fm:8443/ws" ascii
$port_file = "fleetshare_server_port_java.txt" ascii
$hello = "Hello from harvester" ascii
$request = "encryptedRequest" ascii
$ffi = "GetVersion_C called, returning" ascii
condition:
(uint32(0) == 0x464c457f or uint16(0) == 0x5a4d) and
filesize > 256KB and filesize < 150MB and
1 of ($go_package, $src_tree, $port_file, $ffi) and
1 of ($relay, $hello, $request)
}This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.
Indicators of Compromise
File Hashes
| Type | Indicator | Context |
|---|---|---|
| SHA-256 | 021ff84b59a481d41d4dd6417030833c0af7833a140e2b9c184d5586fc4b7cf5 | Confirmed files; FleetSDK |
| SHA-256 | 02cfd75a5edaa2235699a7a2388a06dbdd0b76f278a234dadddac951a892402f | Confirmed files; FleetSDK |
| SHA-256 | 04d51bae3a1627672c61936046c659625cc6e4a691acb3f69930f789d5fd77e9 | Confirmed files; FleetSDK |
| SHA-256 | 067f0e131966ab31fc76c2ff2d40a726949e9deb37c364349cbb6b2ed2c9c1a8 | Confirmed files; FleetSDK |
| SHA-256 | 0989e7c05f6ab8d34fc058521e73d298d8620298b0f400c4551c39ae4e82bf65 | Confirmed files; FleetSDK |
| SHA-256 | 0dcb68b399a6707d8cfc61426052aba29536f17f46d8eed144afc7ccaf87d967 | Confirmed files; FleetSDK |
| SHA-256 | 0df6e6fbf264180e35089c3d216e319de33712ee602d8e17e87b4d9c8bdc9e39 | Confirmed files; FleetSDK |
| SHA-256 | 10761066a5392a137aaf26cbf28c6aaa4c76fd187f0a9130862c38b390553449 | Confirmed files; FleetSDK |
| SHA-256 | 114e84b1048785f8be7ba9e791e9da8e4fe5c84d41cab83d3edb1f12d12699b4 | Confirmed files; FleetSDK |
| SHA-256 | 12f7819c3096d535b60753e0b8b3f3dced119c900c5d88054c561708949ae915 | Confirmed files; FleetSDK |
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
- Type
- SHA-256
- Context
- Confirmed files; FleetSDK
Domains
| Type | Indicator | Context |
|---|---|---|
| Domain | socket-backup[.]earn[.]fm | Tier 2; FleetSDK |
| Domain | geo-loadbalanced[.]com | Tier 2; FleetSDK |
| Domain | socket-eu[.]geo-loadbalanced[.]com:8443 | Backconnect Relays; FleetSDK |
| Domain | socket-prod-ncf[.]geo-loadbalanced[.]com:8443 | Backconnect Relays; FleetSDK |
| Domain | socket-prod[.]earn[.]fm:8443 | Backconnect Relays; FleetSDK |
| Domain | socket-ssl[.]geo-loadbalanced[.]com:8443 | Backconnect Relays; FleetSDK |
| Domain | socket-us[.]geo-loadbalanced[.]com:8443 | Backconnect Relays; FleetSDK |
- Type
- Domain
- Indicator
- Context
- Tier 2; FleetSDK
- Type
- Domain
- Indicator
- Context
- Tier 2; FleetSDK
- Type
- Domain
- Context
- Backconnect Relays; FleetSDK
- Type
- Domain
- Context
- Backconnect Relays; FleetSDK
- Type
- Domain
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- Domain
- Context
- Backconnect Relays; FleetSDK
- Type
- Domain
- Context
- Backconnect Relays; FleetSDK
IP Addresses
| Type | Indicator | Context |
|---|---|---|
| IP address | 5[.]161[.]16[.]74:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]17[.]86:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]17[.]205:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]20[.]68:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]20[.]73:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]21[.]35:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]21[.]219:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]22[.]90:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]22[.]203:8443 | Backconnect Relays; FleetSDK |
| IP address | 5[.]161[.]22[.]218:8443 | Backconnect Relays; FleetSDK |
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; FleetSDK
Research updated September 28, 2026. Last-seen observations change continuously; verify an address with the live lookup before acting.
Additional IOCs are hidden.
Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.
7-day activity
Illustrative preview
See the activity behind the provider.
Unlock daily events and unique IP trends to understand how this provider’s network changes over time.