PACKETSTREAM
Provider- Website
packetstream[.]io
PacketStream is a United States company which has been in operation since 2018. They are known for their low-cost peer-to-peer residential proxy network and direct paid bandwidth-sharing client and are considered a small sized proxy provider. Synthient's Research Team has found proxy resellers such as HydraProxy, TorchProxies, and WiredProxies to be providing access to PacketStream. These indirect sales channels highlight a potential risk due to limited downstream regulation or KYC controls.
PacketStream is observed leveraging its PacketStream client to obtain large swaths of IP addresses. PacketStream is distributed across Windows, Linux, and macOS, is classified as Pay-Bandwidth, and has been observed in the PacketStream Windows, Linux, and macOS clients.
Synthient's Research Team assigns a LOW risk score to PacketStream based on a randomized sample of consent practices observed in the wild.
Reseller Graph
The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.
Yara Rules
rule Proxyware_Packetstream_MultiPlatform_PsclientCore
{
meta:
description = "PacketStream Packeter Go exit-node core for Linux, Windows, and macOS"
provider = "Packetstream"
sdk = "Packetstream"
platform = "Linux ELF, Windows PE, macOS Mach-O"
variant = "psclient"
category = "proxyware"
author = "Synthient"
date = "2026-08-27"
confidence = "high"
intel_family = "packetstream-packeter"
strings:
$module = "github.com/packetstream/ecosystem/exit-node/core" ascii
$api = "https://api.packetstream.io/exitnode/ipinfo/" ascii
$master = "client.packetstream.io" ascii
$update = "client-dl.packetstream.io/dist/version.json.asc" ascii
$auth = "PS_CLIENT_AUTH" ascii
$docker = "PS_IS_DOCKER" ascii
$http = "HTTP/1.1 200 Connection Established\r\nProxy-agent: Proxy\r\n\r\n" ascii
condition:
(uint32(0) == 0x464c457f or uint16(0) == 0x5a4d or
uint32(0) == 0xfeedfacf) and
filesize > 1MB and filesize < 80MB and
$module and
3 of ($api, $master, $update, $auth, $docker, $http)
}This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.
Indicators of Compromise
File Hashes
- Type
- SHA-256
- Context
psclient.exesigned by PacketStream Inc
- Type
- SHA-256
- Context
- PacketStream
psclientELF
- Type
- SHA-256
- Context
psclient.exe.traybaksigned by PacketStream Inc
- Type
- SHA-256
- Context
- Unnamed PacketStream ELF client component
- Type
- SHA-256
- Context
- Confirmed files; Packetstream
- Type
- SHA-256
- Context
- Confirmed files; Packetstream
- Type
- SHA-256
- Context
- Confirmed files; Packetstream
- Type
- SHA-256
- Context
- Confirmed files; Packetstream
- Type
- SHA-256
- Context
- Confirmed files; Packetstream
- Type
- SHA-256
- Context
- Confirmed files; Packetstream
Domains
| Type | Indicator | Context |
|---|---|---|
| Domain | client[.]packetstream[.]io:30944 | Backconnect relay |
| Domain | client[.]packetstream[.]io:30946 | Backconnect relay |
| Domain | api[.]packetstream[.]io | VT-observed client API endpoint |
| Domain | client-dl[.]packetstream[.]io | VT-observed client download endpoint |
- Type
- Domain
- Indicator
- Context
- Backconnect relay
- Type
- Domain
- Indicator
- Context
- Backconnect relay
- Type
- Domain
- Indicator
- Context
- VT-observed client API endpoint
- Type
- Domain
- Indicator
- Context
- VT-observed client download endpoint
IP Addresses
No confirmed ip addresses are included in the reviewed source corpus.
Additional IOCs are hidden.
Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.
7-day activity
Illustrative preview
See the activity behind the provider.
Unlock daily events and unique IP trends to understand how this provider’s network changes over time.