A
e C E e ge c VPN A a
Ri k Le e
High
i
De c i i
E
a ai
Information
Leaked Via
Insecure HTTP
Requests
The mobile device is communicating without encryption
plain HTTP with several websites These insecure
connections leak information about the user increasing the
security risk of the user The information leaked includes
but is not limited to operating system type operating
system name and version public IP address and some of
the applications installed The public IP address is
considered high risk sensitive information because it can be
used to physically locate the user We recommend
uninstalling all applications that are not strictly necessary
and avoid opening links using the Facebook app Use a
VPN when using public and not trusted networks
High
WeChat or QQ
Application Leaks
Data
The WeChat application connects to a WeChat servers
203 205 219 149 203 205 219 208 on port 9000 sending
important information about the device in clear text not
using encryption The information leaked includes a unique
user ID device ID and current version These values can
be used to unequivocally identify the device in large
amounts of data We recommend uninstalling the WeChat
application immediately
High
Suspicious
connection
attempts
to IP
203 205 146 46
The mobile phone performs multiple connection attempts to
IP address 203 205 146 46 on ports 14000 TCP 443 TCP
80 TCP and 8080 TCP The connections are never
established meaning that the phone is unable to transfer
and exchange information with the server This is highly
usual in a mobile device
Suspicious
behavior
associated with
sandai net
The mobile device is performing repetitive connections to a
non existing domain res res res res on port 80 These
connections are sent to multiple IP addresses The data
transferred seems to be encrypted The IP addresses are
associated with sandai net which has been tied to
malicious applications We recommend factory reset your
mobile device to make sure this behavior stops
Phone IMEI
Leaked
in Plain Text to
Baidu Servers
The mobile phone communicates with Baidu servers using
the HTTP insecure protocol leaking device and personal
information in the network without encryption The
information leaked includes IMEI language application
mobile phone type and version operating system version
SDK and others This cannot be avoided unless the user
stops using Baidu applications
High
High