Researchers Link Peer2Profit to Astroproxy and Demonstrate DNS-Based Access to Internal Networks

Summary
Silent Push researchers confirmed Astroproxy resells Peer2Profit bandwidth and found its proxy network could reach internal resources when a DNS name resolved to an internal IP, despite a filter blocking direct internal-IP requests.
Key points
- Researchers enrolled a test device in Peer2Profit and saw its residential IP appear in Astroproxy’s proxy pool about 10 minutes later, confirming an active operational relationship.
- A 72-hour enumeration identified 117,224 unique IPs across Astroproxy’s residential, datacenter, and mobile pools; the residential pool added an average of 1,071 new IPs per hour.
- Reverse-engineering Peer2Profit’s Windows SDK revealed device registration with its API and persistent connections to backconnect servers that relay proxy requests using a custom protocol with nibble-inversion encoding.
- Astroproxy blocked direct requests to internal IP addresses, but researchers bypassed the filter using a domain name resolving to an internal address and reached a MEO residential router management interface.
- Researchers said they disclosed the internal-access issue before publication, but Astroproxy had not meaningfully remediated it by then.
- Peer2Profit is presented as a consent-based bandwidth-sharing app, not malware; if installed on a corporate-connected device, it can expose the organization’s public IP as a proxy exit and potentially provide access to internal resources.
- The researchers noted that rapidly rotating proxy IPs limit reactive reputation-based detection, while the coordinating backconnect infrastructure was more stable and concentrated among four hosting providers.
Article Details
- Attack Vectors
- An employee can voluntarily install PEER2PROFIT on a device connected to a corporate network, making that connection available as an ASTROPROXY exit node.
- Silent Push demonstrated that a domain resolving to an internal IP address bypassed ASTROPROXY's block on direct requests to internal IP ranges. Through an enrolled node, the researchers reached a residential router management interface and downloaded a PNG file.
- The article reports threat actors abusing residential proxy networks for credential stuffing, malspam, financial and banking fraud, geo-restriction bypass, and rate-limit evasion. It does not attribute those activities to a named actor in this investigation.
- According to research cited in the article, the PEER2PROFIT SDK had also been mass-installed through PPI botnets such as PRIVATELOADER.
- Defensive Notes
- The article states that PEER2PROFIT is not malware and that ordinary antivirus and reputation-based feeds may not flag its client or coordinating infrastructure.
- Silent Push recommends proactively enumerating proxy networks and tracking their coordinating infrastructure and currently active exit nodes rather than relying only on historical IP reputation.
- The internal-network access finding was disclosed to the provider before publication; Silent Push reports that it had not been meaningfully remediated.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | api[.]peer2profit[.]global | PEER2PROFIT device-registration API used to obtain backconnect server configuration. |
| IPV4 | 135[.]181[.]73[.]138 | Historical proxy-service infrastructure whose shared SSL certificate linked PEER2PROFIT and ASTROPROXY. |
| IPV4 | 137[.]74[.]6[.]101 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 137[.]74[.]7[.]212 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 139[.]99[.]64[.]101 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 139[.]99[.]64[.]102 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 139[.]99[.]64[.]113 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 139[.]99[.]64[.]99 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 145[.]239[.]16[.]66 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 145[.]239[.]21[.]108 | Backconnect server address shown in a PEER2PROFIT device-registration response. |
| IPV4 | 147[.]135[.]199[.]160 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 147[.]135[.]199[.]185 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 147[.]135[.]199[.]186 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 162[.]19[.]83[.]163 | Historical proxy-service infrastructure whose shared SSL certificate linked PEER2PROFIT and ASTROPROXY. |
| IPV4 | 172[.]241[.]25[.]105 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 172[.]241[.]25[.]106 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 172[.]241[.]25[.]107 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 185[.]35[.]223[.]163 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 185[.]35[.]223[.]164 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 185[.]35[.]223[.]165 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 185[.]35[.]223[.]166 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]44 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]47 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]48 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]49 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]50 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]51 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]53 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]55 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]56 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 45[.]10[.]174[.]57 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 51[.]79[.]133[.]114 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 51[.]89[.]238[.]177 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 51[.]89[.]238[.]184 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 54[.]38[.]210[.]140 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 54[.]38[.]210[.]145 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 54[.]38[.]210[.]150 | PEER2PROFIT backconnect server listed by Silent Push. |
| IPV4 | 94[.]130[.]135[.]167 | Historical proxy-service infrastructure whose shared SSL certificate linked PEER2PROFIT and ASTROPROXY. |
| SHA256 | 0b10a1e48df2884a7a8a1ebf5aa903207955433c8ea00d7602c78be6e6c177cc | PEER2PROFIT Windows SDK sample analyzed and listed in the sample appendix; the article says the app is not malware. |
| SHA256 | 8871d12a7bb7529ff6e90ad5a18c86e92a402a2d02d3283d1385bdb52ba2b0f2 | PEER2PROFIT DMG sample listed in the research appendix; the article does not classify it as malware. |
| SHA256 | c85c7436fdb71cf52db6ef134b336d66c7dbd3738a7866f8b9992434d1208a4b | PEER2PROFIT APK sample listed in the research appendix; the article does not classify it as malware. |
MITRE ATT&CK
T1090.002 · External ProxyThe article reports threat actors routing activity through residential proxy networks so traffic appears to originate from ordinary users' IP addresses.T1110.004 · Credential StuffingThe article reports threat actors abusing residential proxy networks for large-scale credential stuffing.
Malware
Vendors
Products
Countries
BrazilPortugal, Ukraine, and Brazil follow. The distribution spans every major region, reflecting the global reach of bandwidth-sharing programs.FranceGermanyThe datacenter pool is more geographically concentrated, with the United States alone accounting for nearly 47% of observed IPs, followed by Vietnam and Germany.IndiaRussia and India lead, followed by Italy, Ukraine, and Spain, all served by legitimate national carriers.ItalyRussia and India lead, followed by Italy, Ukraine, and Spain, all served by legitimate national carriers.KazakhstanPortugalPortugal, Ukraine, and Brazil follow. The distribution spans every major region, reflecting the global reach of bandwidth-sharing programs.RussiaThe residential pool is dominated by Russia and Vietnam, which together account for over 40% of all observed IPs.SpainRussia and India lead, followed by Italy, Ukraine, and Spain, all served by legitimate national carriers.UkrainePortugal, Ukraine, and Brazil follow. The distribution spans every major region, reflecting the global reach of bandwidth-sharing programs.United StatesThe datacenter pool is more geographically concentrated, with the United States alone accounting for nearly 47% of observed IPs, followed by Vietnam and Germany.VietnamThe residential pool is dominated by Russia and Vietnam, which together account for over 40% of all observed IPs.