SHIFTER
Provider- Website
shifter[.]io
Shifter is a company of unverified jurisdiction which has been in operation since 2012. They are known for residential and ISP proxies and web-scraping APIs and are provisionally considered a large sized proxy provider based on their advertised 205-million IP pool. Synthient's Research Team did not verify a named downstream reseller in the reviewed corpus. A reseller's regulation or KYC practices cannot be inferred from shared hosting or provider marketing claims. Operating history and advertised scale.
Shifter is observed leveraging Microleaves / Online Guardian to obtain IP addresses, with the SDK distributed across Windows. The Microleaves components are classified as App Monetization / proxyware and can be observed in Online Guardian and Advanced Windows Manager. VirusTotal signatures and product metadata support those names but do not establish a complete list of third-party applications or Shifter's current supply mix.
Synthient's Research Team assigns a provisional MEDIUM risk score to the reviewed Microleaves components based on a targeted component sample, not a randomized survey. Static inspection of Advanced Windows Manager identifies the relay core but does not establish an end-user consent flow, and available sandbox records do not resolve that gap.
Reseller Graph
The highlighted node is the provider named on this card. Reseller arrows point toward that provider. App, SDK, and supply associations are labeled separately and do not establish ownership.
Yara Rules
import "pe"
rule Proxyware_Microleaves_Windows_SDK
{
meta:
description = "Shifter Microleaves Windows proxy SDK implementation"
provider = "Shifter"
sdk = "Microleaves"
platform = "Windows PE/EXE (x86 and x64)"
variant = "Online Guardian / AdvancedWindowsManager core"
category = "proxyware"
author = "Synthient"
date = "2026-08-31"
confidence = "high"
intel_family = "shifter-microleaves"
strings:
$modern_tracker_dynamic = "%lu.t.online.io" ascii
$modern_tracker_static = "71.t.online.io" ascii
$modern_agent = "Proxy-agent: Online_Application" ascii
$modern_fetch = "Trying to fetch Instance" ascii
$modern_assignment = "Couldnt get instance from tracker." ascii
$modern_success = "SUCCESS connecting to instance.Sending FD" ascii
$modern_domain = "Domain Rules: %s" ascii
$modern_http_ports = "HPort Rules: %s" ascii
$modern_special_ports = "SPort Rules: %s" ascii
$legacy_source = "OnlineGuardian\\g\\htrack.c" ascii
$legacy_agent = "Proxy-agent: OIOGuradian" ascii
$legacy_tracker = "t.online.io" ascii
$legacy_retry = "No Instance..will retry" ascii
$legacy_connected = "HTTP/1.0 200 Connection Established" ascii
$servant_target = "Target: %s Port: %s" ascii
$servant_target_error = "ERROR connecting target" ascii
$servant_relay_error = "ERROR connecting servant" ascii
$servant_contact = "contact@online.io" ascii
$embedded_agent = "Proxy-Agent: v1.1.0" ascii
$embedded_blocked = "This request is not allowed due to ACL policy. Domain or IP is blocked, unblock it from panel." ascii
$embedded_fetch = "Trying to fetch instance from t" ascii
$embedded_success = "SUCCESS connecting to i.Sending FD" ascii
$embedded_domain = "Domain Rules: %s" ascii
$embedded_http_ports = "HPort Rules: %s" ascii
$embedded_special_ports = "SPort Rules: %s" ascii
$embedded_tracker_port = "tracker-port" ascii fullword
$embedded_instance_addr = "instance-addr" ascii fullword
$embedded_instance_port = "instance-port" ascii fullword
$v2_parse = "cannot parse packet from tracker: %d (%s)" ascii
$v2_invalid = "received invalid address/port from tracker" ascii
$v2_assignment = "received instance address from tracker: %s:%u" ascii
$v2_log = "[proto-tracker]" ascii
$v2_connect = "cannot connect to the instance: %s (code %d)" ascii
$v2_opcode = "server does not support operation code: [%u]" ascii
$v2_build = "starting (v2025041411) in %s mode ..." ascii
condition:
uint16(0) == 0x5a4d and
not pe.is_dll() and
filesize > 64KB and filesize < 2MB and
(
(
1 of ($modern_tracker_*) and $modern_agent and
3 of ($modern_fetch, $modern_assignment, $modern_success,
$modern_domain, $modern_http_ports, $modern_special_ports)
) or
4 of ($legacy_source, $legacy_agent, $legacy_tracker,
$legacy_retry, $legacy_connected) or
all of ($servant_*) or
(
all of ($embedded_tracker_port, $embedded_instance_addr,
$embedded_instance_port) and
4 of ($embedded_agent, $embedded_blocked, $embedded_fetch,
$embedded_success, $embedded_domain,
$embedded_http_ports, $embedded_special_ports)
) or
(
all of ($embedded_tracker_port, $embedded_instance_addr,
$embedded_instance_port) and
5 of ($v2_parse, $v2_invalid, $v2_assignment, $v2_log,
$v2_connect, $v2_opcode, $v2_build)
)
)
}This rule identifies an SDK family. A match alone does not establish malicious activity or the absence of consent.
Indicators of Compromise
File Hashes
- Type
- SHA-256
- Context
- Online Guardian; Microleaves-signed Windows component
- Type
- SHA-256
- Context
- Advanced Windows Manager; statically inspected relay core
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
- Type
- SHA-256
- Context
- Confirmed files; Microleaves
Domains
| Type | Indicator | Context |
|---|---|---|
| Domain | t[.]online[.]io | Tracker marker in the published rule |
| Domain | 71[.]t[.]online[.]io | Tracker marker in the published rule |
| Domain | 0[.]t[.]dancevalidator[.]com:8080 | Tier 1; Microleaves |
| Domain | 0[.]t[.]dancevalidator[.]io:8443 | Tier 1; Microleaves |
| Domain | 0[.]t[.]keepitpumpin[.]io:8080 | Tier 1; Microleaves |
| Domain | 0[.]t[.]keepitpumpin[.]io:8443 | Tier 1; Microleaves |
| Domain | 0[.]t[.]online[.]io:8891 | Tier 1; Microleaves |
| Domain | 71[.]t[.]online[.]io:8891 | Tier 1; Microleaves |
| Domain | t[.]online[.]io:8889 | Tier 1; Microleaves |
- Type
- Domain
- Indicator
- Context
- Tracker marker in the published rule
- Type
- Domain
- Indicator
- Context
- Tracker marker in the published rule
- Type
- Domain
- Indicator
- Context
- Tier 1; Microleaves
- Type
- Domain
- Indicator
- Context
- Tier 1; Microleaves
- Type
- Domain
- Indicator
- Context
- Tier 1; Microleaves
- Type
- Domain
- Indicator
- Context
- Tier 1; Microleaves
- Type
- Domain
- Indicator
- Context
- Tier 1; Microleaves
- Type
- Domain
- Indicator
- Context
- Tier 1; Microleaves
- Type
- Domain
- Indicator
- Context
- Tier 1; Microleaves
IP Addresses
| Type | Indicator | Context |
|---|---|---|
| IP address | 62[.]210[.]9[.]152:8891 | Tier 1; Microleaves |
| IP address | 62[.]210[.]169[.]113:8888 | Tier 1; Microleaves |
| IP address | 104[.]156[.]155[.]94:8443 | Tier 1; Microleaves |
| IP address | 208[.]117[.]43[.]222:8443 | Tier 1; Microleaves |
| IP address | 212[.]83[.]161[.]135:8891 | Tier 1; Microleaves |
| IP address | 62[.]210[.]169[.]113:8891 | Backconnect Relays; Microleaves |
- Type
- IP address
- Indicator
- Context
- Tier 1; Microleaves
- Type
- IP address
- Indicator
- Context
- Tier 1; Microleaves
- Type
- IP address
- Indicator
- Context
- Tier 1; Microleaves
- Type
- IP address
- Indicator
- Context
- Tier 1; Microleaves
- Type
- IP address
- Indicator
- Context
- Tier 1; Microleaves
- Type
- IP address
- Indicator
- Context
- Backconnect Relays; Microleaves
Additional IOCs are hidden.
Available to subscribers. This preview shows up to ten IP addresses, ten domains, and ten file hashes.
7-day activity
Illustrative preview
See the activity behind the provider.
Unlock daily events and unique IP trends to understand how this provider’s network changes over time.