GETGRASS
Providerproxy provider intelligence profile
- Website
grass[.]io
GetGrass is a Canadian-origin company which has been in operation since 2023. They are known for residential web-data collection, AI training datasets, and rewarding users for unused bandwidth and are considered a large sized proxy provider. Synthient's Research Team found no confirmed third-party proxy reseller providing access to GetGrass in the reviewed corpus; its public model instead supplies undisclosed institutional data customers through the first-party Grass Network. The lack of visibility into those downstream customers may create regulation or KYC risk.
GetGrass is observed leveraging its own GetGrass / Wynd node SDK to source IP addresses, with the SDK distributed across Android, Windows, macOS, Linux, and Chromium browsers. The GetGrass SDK is classified as Pay-Bandwidth and can be observed in Grass for Android, Grass Desktop Node, and the Grass Lite and Community browser nodes.
Synthient's Research Team assigns a LOW risk score to GetGrass SDK based on a randomized sample of consent practices observed in the wild. The reviewed software is distributed as dedicated, first-party bandwidth-sharing software with account enrollment, visible connection state, and pause controls; operational proxy-exit and ISP-policy risks remain.
Research record
| Field | Finding |
|---|---|
| Operator / jurisdiction | Grass / Wynd · Canadian origin |
| Operating history | Operating since 2023 |
| Network type | Residential, browser-node, desktop-node, and SDK-sourced bandwidth-sharing network |
| Verified channels | First-party Grass Network; no confirmed third-party proxy reseller in the reviewed corpus |
| SDK / platforms | GetGrass / Wynd node SDK · Android, Windows, macOS, Linux, and Chromium browsers · pay-bandwidth |
| Consent / KYC | LOW consent-risk rating from a randomized review; numeric sample size is not public and institutional-customer KYC was not independently sampled |
| Infrastructure | Grass Android, Desktop Node, Lite node, and Community node are observed applications; domains, certificates, hashes, and IPs appear below |
| Review dates | Research updated 2026-09-28 · use the live lookup for current last-seen network observations |
- Field
- Operator / jurisdiction
- Finding
- Grass / Wynd · Canadian origin
- Field
- Operating history
- Finding
- Operating since 2023
- Field
- Network type
- Finding
- Residential, browser-node, desktop-node, and SDK-sourced bandwidth-sharing network
- Field
- Verified channels
- Finding
- First-party Grass Network; no confirmed third-party proxy reseller in the reviewed corpus
- Field
- SDK / platforms
- Finding
- GetGrass / Wynd node SDK · Android, Windows, macOS, Linux, and Chromium browsers · pay-bandwidth
- Field
- Consent / KYC
- Finding
- LOW consent-risk rating from a randomized review; numeric sample size is not public and institutional-customer KYC was not independently sampled
- Field
- Infrastructure
- Finding
- Grass Android, Desktop Node, Lite node, and Community node are observed applications; domains, certificates, hashes, and IPs appear below
- Field
- Review dates
- Finding
- Research updated 2026-09-28 · use the live lookup for current last-seen network observations
Reseller Graph
The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.
Yara Rules
rule Proxyware_GetGrass_Android_Package
{
meta:
description = "Android package shipping the Grass node: io.getgrass.www host plus the rust_wynd_proxy core"
provider = "Getgrass"
sdk = "GetGrass"
platform = "Android APK"
variant = "host-package"
scope = "APK container; matches on the stored entry names and resource table"
category = "proxyware"
author = "Synthient"
date = "2026-08-27"
confidence = "high"
intel_family = "grass"
strings:
$pkg_dotted = "io.getgrass.www" ascii
$pkg_path = "io/getgrass/" ascii
$lib = "librust_wynd_proxy.so" ascii
$rust = "rust_wynd_proxy" ascii
$plugin = "io/getgrass/plugin" ascii
$kek = "grass_seed_kek" ascii
$dek = "grass_dek.bin" ascii
condition:
uint32(0) == 0x04034b50 and
filesize > 1MB and filesize < 300MB and
1 of ($pkg_*) and
2 of ($lib, $rust, $plugin, $kek, $dek)
}This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.
Indicators of Compromise
File Hashes
- Type
- SHA-256
- Context
- Legacy Grass Android 0.30.3 client
- Type
- SHA-256
- Context
- Current-generation Android host package
- Type
- SHA-256
- Context
- Android
rust_wynd_proxynative core
- Type
- SHA-256
- Context
- Signed Grass browser-node CRX
- Type
- SHA-256
- Context
- Windows Grass Desktop Node
- Type
- SHA-256
- Context
- macOS Grass Desktop Node
- Type
- SHA-256
- Context
- Linux Grass Desktop Node
- Type
- SHA-256
- Context
- Confirmed files; GetGrass
- Type
- SHA-256
- Context
- Confirmed files; GetGrass
- Type
- SHA-256
- Context
- Confirmed files; GetGrass
Domains
| Type | Indicator | Context |
|---|---|---|
| Domain | api[.]getgrass[.]io | Legacy API and control plane |
| Domain | mobile[.]getgrass[.]io | Legacy mobile application shell |
| Domain | director[.]getgrass[.]io | Node director service |
| Domain | director[.]grass[.]io | Current director namespace |
| Domain | proxy[.]wynd[.]network:4650 | Relay and gateway service |
| Domain | ws-server[.]aws-wynd[.]com | WebSocket relay namespace |
- Type
- Domain
- Indicator
- Context
- Legacy API and control plane
- Type
- Domain
- Indicator
- Context
- Legacy mobile application shell
- Type
- Domain
- Indicator
- Context
- Node director service
- Type
- Domain
- Indicator
- Context
- Current director namespace
- Type
- Domain
- Indicator
- Context
- Relay and gateway service
- Type
- Domain
- Indicator
- Context
- WebSocket relay namespace
IP Addresses
| Type | Indicator | Context |
|---|---|---|
| IP address | 18[.]209[.]133[.]16 | Observed AWS relay for proxy.wynd.network |
| IP address | 34[.]197[.]157[.]38 | Observed AWS relay for proxy.wynd.network |
| IP address | 54[.]86[.]220[.]122 | Observed AWS relay for proxy.wynd.network |
- Type
- IP address
- Indicator
- Context
- Observed AWS relay for
proxy.wynd.network
- Type
- IP address
- Indicator
- Context
- Observed AWS relay for
proxy.wynd.network
- Type
- IP address
- Indicator
- Context
- Observed AWS relay for
proxy.wynd.network
Research updated September 28, 2026. Last-seen observations change continuously; verify an address with the live lookup before acting.
Additional IOCs are hidden.
Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.
7-day activity
Illustrative preview
See the activity behind the provider.
Unlock daily events and unique IP trends to understand how this provider’s network changes over time.