Candy Crush Jelly
Application
Communicates
Insecurely
The mobile device is communicating with the server
candycrushjelly king com using the insecure HTTP protocol
on port 80 TCP These insecure communications leak
device and user information including possible friends
names in Facebook how the user is connected to them
and their profile pictures We recommend uninstalling this
application immediately
Joox Music
Application Leaks
Personal Data
The application Joox Music is communicating using the
HTTP insecure protocol leaking device and personal
information in the network without encryption The
information leaked includes country mobile carrier name
operating system current phone orientation device model
application name network type network operator
language and gender among others We recommend
uninstalling this application immediately
Medium
Suspicious
Connection to
Server
119 28 109 138
port
8002
The mobile device is communicating with server
119 28 109 138 on port 8002 The communication is in a
non standard port The data transferred appears to be
encrypted The owner of the IP is Tencent however we
could not associate this specific behavior with any particular
application We recommend uninstalling all non essential
applications and perform this analysis again to make sure
this behavior is no longer happening
Medium
There are multiple requests to the host loc map baidu com
This host is related to multiple malicious applications It
Suspicious domain could be an indicator of unwanted behavior in the mobile
name contacted:
phone We suggest factory reset the phone and keeping
loc map baidu com applications installed to the essential
Medium
The mobile device is communicating without encryption
plain HTTP with several websites These insecure
connections leak information about the user increasing the
security risk of the user The information leaked includes
but is not limited to operating system type name and
Information
version internet connection type and some of the
Leaked
applications installed We recommend uninstalling all
Via Insecure HTTP applications that are not strictly necessary Use a VPN
Requests
when using public and not trusted networks
Low
The mobile device is communicating without encryption
plain HTTP with several websites These insecure
connections leak information about the user increasing the
security risk of the user The information leaked includes
but is not limited to operating system type name and
Information
version public IP address device type and some of the
Leaked
applications installed We recommend uninstalling all
Via Insecure HTTP applications that are not strictly necessary Use a VPN
Requests
when using public and not trusted networks
High
High