0/61

Threat

in.workindia.nileshdungarwal.workindiaandroid

WorkIndia

Analyzed on 2021-08-21T06:53:41.087769

30

permissions

66

activities

26

services

18

receivers

46

domains

File sums

MD5 b6d9b47966270989ca5948c5a5b9cced
SHA1 f8cde98a64c77ae5a96210bb27a767b097ed1dd2
SHA256 af60530ea771c22a31f21a33907e928b5daed0110e14e6a4d137ec39613eaf7c
Size 9.51MB

APKiD

Information computed with APKiD.

/tmp/tmpy92s8527!classes.dex
anti_vm
  • Build.FINGERPRINT check
  • Build.MODEL check
  • Build.MANUFACTURER check
  • Build.PRODUCT check
  • Build.TAGS check
  • SIM operator check
  • network operator name check
  • device ID check
  • subscriber ID check
anti_debug
  • Debug.isDebuggerConnected() check
compiler
  • r8
/tmp/tmpy92s8527!classes2.dex
anti_vm
  • Build.MODEL check
  • Build.MANUFACTURER check
compiler
  • r8 without marker (suspicious)

SSdeep

Information computed with ssdeep.

APK file 196608:E4s/GS1x2Pi2cxuvEnYUFQxaCu1VkUBhkb5ukYaQAu3mdD91:NsSKnxMlav1bXkbkkv43u1
Manifest 768:zzFp8bCqZcJgMUQt9vv9OIhA8Z/bJ/93y/AbGAazuQsIKcC+YzUTCMsSUrx01KlG:…
classes.dex 98304:VnRUlEZvZsTvkEToyJjpU8CLsJcA5V3HrwIAFgk:6qvHSoGyA35AFgk
classes2.dex 24576:giRAnpk6i1oRbbf+I8NH1k7uyVf6bzI4SVkn7t46g7BwipZPPz1eZcY/QRB4C6T…

Dexofuzzy

Information computed with Dexofuzzy.

APK file 12288:AIAyde3afFhyeKYvm4laT6VVXi5g2FQ/TKk:Ace3afTlKY2MQgkQrKk
classes.dex 6144:touGIAyM9MKC43aXvmFIvwew/+UmECrYp8KYS3KRHkXsL3NfCGrBa1LEIxuBHM2J…
classes2.dex 1536:iWUyo7PH/TlGt5/0hSsFA66tRF3/6Js/OE1PSX4EdSf47GRj2WK7iEk:LFCPbEt5…

APK details

Information computed with AndroGuard and Pithus.

Package in.workindia.nileshdungarwal.workindiaandroid
App name WorkIndia
Version name 7.0.1.3
Version code 501
SDK 16 - 29
UAID bf7010ab08628efbd1c55e4d45f726bc10c8e932
Signature Signature V1 Signature V2 Signature V3
Frosting Not frosted
Blocks found within V2 signature:
  • 0x7109871a: Unknown
  • 0xf05368c0: Unknown
  • 0x6dff800d: Source stamp V2 X509 cert
  • 0x42726577: Verity padding

Certificate details

Information computed with AndroGuard.

MD5 c47446d10c7a53d63b2f43c2e34ce656
SHA1 2e328de1bc8d9844c8a7634fa66f9363c00f613d
SHA256 0fdc1fed6cd07d2c4854153ee799955c35f5dd671743e3c4610c90914d2f7d32
Issuer Common Name: Nilesh Dungarwal, Organizational Unit: WorkIndia, Organization: WorkIndia, Locality: Mumbai, State/Province: Maharashtra, Country: IN
Not before 2015-06-28T16:40:40+00:00
Not after 2040-06-21T16:40:40+00:00

File Analysis

Information computed with MobSF.

Findings Files
Certificate/Key files hardcoded inside the app. okhttp3/internal/publicsuffix/NOTICE
stamp-cert-sha256

Manifest analysis

Information computed with MobSF.

High Clear text traffic is Enabled For App[android:usesCleartextTraffic=true]
The app intends to use cleartext network traffic, such as cleartext HTTP, FTP stacks, DownloadManager, and MediaPlayer. The default value for apps that target API level 27 or lower is "true". Apps that target API level 28 or higher default to "false". The key reason for avoiding cleartext traffic is the lack of confidentiality, authenticity, and protections against tampering; a network attacker can eavesdrop on transmitted data and also modify it without being detected.
High Activity (in.workindia.nileshdungarwal.workindiaandroid.SearchActivity) is not Protected.An intent-filter exists.
An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.SplashScreenActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.RegisterActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Activity (in.workindia.nileshdungarwal.workindiaandroid.RegisterActivity) is not Protected. [android:exported=true]
An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.BlankBranchShareActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Activity (in.workindia.nileshdungarwal.workindiaandroid.BlankBranchShareActivity) is not Protected.An intent-filter exists.
An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.StreamingMp3PlayerActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.PlayMediaActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Activity (in.workindia.nileshdungarwal.workindiaandroid.JobLongDescriptionActivity) is not Protected. [android:exported=true]
An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Activity (in.workindia.nileshdungarwal.workindiaandroid.goverment_jobs.GovernmentJobLongDescriptionActivity) is not Protected. [android:exported=true]
An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.FirstFillProfileActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.JobAddressActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Activity (in.workindia.nileshdungarwal.workindiaandroid.JobAddressActivity) is not Protected.An intent-filter exists.
An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.SkillQuestionActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.CityActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.SelectSectorActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Launch Mode of Activity (in.workindia.nileshdungarwal.workindiaandroid.MainActivityListV2) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Content Provider (com.facebook.FacebookContentProvider) is not Protected. [android:exported=true]
A Content Provider is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Broadcast Receiver (in.workindia.nileshdungarwal.recievers.CampaignReceiver) is not Protected. [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Broadcast Receiver (com.google.android.gms.analytics.CampaignTrackingReceiver) is not Protected.An intent-filter exists.
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported.
High Broadcast Receiver (in.workindia.nileshdungarwal.recievers.yesnorecievers.CancelNotificationResponse) is not Protected.An intent-filter exists.
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported.
High Broadcast Receiver (in.workindia.nileshdungarwal.recievers.yesnorecievers.YesNoPositiveResponse) is not Protected.An intent-filter exists.
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported.
High Broadcast Receiver (in.workindia.nileshdungarwal.recievers.yesnorecievers.YesNoNegativeResponse) is not Protected.An intent-filter exists.
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported.
High Broadcast Receiver (in.workindia.nileshdungarwal.recievers.yesnorecievers.YesNoCancelResponse) is not Protected.An intent-filter exists.
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported.
High Broadcast Receiver (in.workindia.nileshdungarwal.recievers.PhoneHangupReceiver) is not Protected.An intent-filter exists.
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported.
High Broadcast Receiver (in.workindia.nileshdungarwal.recievers.MySmsReceiver) is not Protected. [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Service (in.workindia.nileshdungarwal.services.MyFcmMessageListenerService) is not Protected.An intent-filter exists.
A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Service is explicitly exported.
High Service (in.workindia.nileshdungarwal.services.CollectIdService) is Protected by a permission, but the protection level of the permission should be checked.
Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]
A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.
High Service (in.workindia.nileshdungarwal.sync.SyncService) is not Protected. [android:exported=true]
A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Service (in.workindia.nileshdungarwal.sync.AccountAuthenticatorService) is not Protected.An intent-filter exists.
A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Service is explicitly exported.
High Content Provider (com.facebook.FacebookContentProvider) is not Protected. [android:exported=true]
A Content Provider is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Broadcast Receiver (com.facebook.CampaignTrackingReceiver) is Protected by a permission, but the protection level of the permission should be checked.
Permission: android.permission.INSTALL_PACKAGES [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.
High Service (com.google.android.gms.auth.api.signin.RevocationBoundService) is Protected by a permission, but the protection level of the permission should be checked.
Permission: com.google.android.gms.auth.api.signin.permission.REVOCATION_NOTIFICATION [android:exported=true]
A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.
High Launch Mode of Activity (com.google.android.play.core.missingsplits.PlayCoreMissingSplitsActivity) is not standard.
An Activity should not be having the launch mode attribute set to "singleTask/singleInstance" as it becomes root Activity and it is possible for other applications to read the contents of the calling Intent. So it is required to use the "standard" launch mode attribute when sensitive information is included in an Intent.
High Service (com.google.android.play.core.assetpacks.AssetPackExtractionService) is not Protected. [android:exported=true]
A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High Broadcast Receiver (com.google.firebase.iid.FirebaseInstanceIdReceiver) is Protected by a permission, but the protection level of the permission should be checked.
Permission: com.google.android.c2dm.permission.SEND [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.

Browsable activities

Information computed with MobSF.

in.workindia.nileshdungarwal.workindiaandroid.SplashScreenActivity

Hosts: jobs

Schemes: in.workindia.nileshdungarwal.workindiaandroid:// workindia://

in.workindia.nileshdungarwal.workindiaandroid.BlankBranchShareActivity

Hosts: open bnc.lt

Schemes: workindia:// https://

in.workindia.nileshdungarwal.workindiaandroid.JobAddressActivity

Hosts: www.workindia.in

Schemes: https:// http://

Main Activity

Information computed with AndroGuard.

['in.workindia.nileshdungarwal.workindiaandroid.AnyJobActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ChromeCustomTabActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ServicesActivity', 'in.workindia.nileshdungarwal.workindiaandroid.JobBoxActivity', 'in.workindia.nileshdungarwal.workindiaandroid.AccountSettingActivity', 'in.workindia.nileshdungarwal.workindiaandroid.CompanyFeedbackActivity', 'in.workindia.nileshdungarwal.workindiaandroid.EmployerUnlockedJobsActivity', 'in.workindia.nileshdungarwal.workindiaandroid.AutofillCityActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ProfileSettingsActivity', 'in.workindia.nileshdungarwal.workindiaandroid.SearchActivity', 'in.workindia.nileshdungarwal.workindiaandroid.SplashScreenActivity', 'in.workindia.nileshdungarwal.workindiaandroid.RegisterActivity', 'in.workindia.nileshdungarwal.workindiaandroid.BlankBranchShareActivity', 'in.workindia.nileshdungarwal.workindiaandroid.StreamingMp3PlayerActivity', 'in.workindia.nileshdungarwal.workindiaandroid.PlayMediaActivity', 'in.workindia.nileshdungarwal.workindiaandroid.FavoriteJobListActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ProfileEditActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ProfilePageActivity', 'in.workindia.nileshdungarwal.workindiaandroid.JobLongDescriptionActivity', 'in.workindia.nileshdungarwal.workindiaandroid.goverment_jobs.GovernmentJobLongDescriptionActivity', 'in.workindia.nileshdungarwal.workindiaandroid.AppliedJobsActivity', 'in.workindia.nileshdungarwal.workindiaandroid.LanguageActivity', 'in.workindia.nileshdungarwal.workindiaandroid.LanguageActivityNew', 'in.workindia.nileshdungarwal.workindiaandroid.SettingsActivity', 'in.workindia.nileshdungarwal.workindiaandroid.NotificationListActivity', 'in.workindia.nileshdungarwal.workindiaandroid.FilterActivity', 'in.workindia.nileshdungarwal.workindiaandroid.MultipleJobViewActivity', 'in.workindia.nileshdungarwal.workindiaandroid.InterviewTipActivity', 'in.workindia.nileshdungarwal.workindiaandroid.FirstFillProfileActivity', 'in.workindia.nileshdungarwal.workindiaandroid.AmezingShare', 'in.workindia.nileshdungarwal.workindiaandroid.RecommendedJobActivityV2', 'in.workindia.nileshdungarwal.workindiaandroid.CreateResumeActivity', 'in.workindia.nileshdungarwal.workindiaandroid.GovernmentJobActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ShareContactActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ShareActivity', 'in.workindia.nileshdungarwal.workindiaandroid.JobAddressActivity', 'in.workindia.nileshdungarwal.workindiaandroid.SkillQuestionActivity', 'in.workindia.nileshdungarwal.workindiaandroid.AddSkillActivity', 'in.workindia.nileshdungarwal.workindiaandroid.SearchSkillActivity', 'in.workindia.nileshdungarwal.workindiaandroid.UploadResumePhotoActivity', 'in.workindia.nileshdungarwal.workindiaandroid.CityActivity', 'in.workindia.nileshdungarwal.workindiaandroid.RecordVoiceActivity', 'in.workindia.nileshdungarwal.workindiaandroid.WriteReviewActivity', 'in.workindia.nileshdungarwal.workindiaandroid.FillJobTitleExperienceActivity', 'in.workindia.nileshdungarwal.workindiaandroid.WorkindiaProfileActivity', 'in.workindia.nileshdungarwal.workindiaandroid.EmployerLeadActivity', 'in.workindia.nileshdungarwal.workindiaandroid.WorkindiaJobWebActivity', 'in.workindia.nileshdungarwal.workindiaandroid.SelectSectorActivity', 'in.workindia.nileshdungarwal.workindiaandroid.LoginActivity', 'in.workindia.nileshdungarwal.workindiaandroid.WebViewActivity', 'in.workindia.nileshdungarwal.workindiaandroid.ResumeBuilderActivity', 'in.workindia.nileshdungarwal.workindiaandroid.HelpAndSupportActivity', 'in.workindia.nileshdungarwal.workindiaandroid.VerifyOtpActivity', 'in.workindia.nileshdungarwal.workindiaandroid.MainActivityListV2', 'in.workindia.nileshdungarwal.workindiaandroid.ProfileEditNewActivity', 'in.workindia.nileshdungarwal.workindiaandroid.nps.NpsResponseReasonActivity', 'com.theartofdev.edmodo.cropper.CropImageActivity', 'com.facebook.FacebookActivity', 'com.facebook.CustomTabMainActivity', 'com.facebook.CustomTabActivity', 'com.google.android.libraries.places.widget.AutocompleteActivity', 'com.google.android.gms.auth.api.signin.internal.SignInHubActivity', 'pub.devrel.easypermissions.AppSettingsDialogHolderActivity', 'com.google.android.play.core.missingsplits.PlayCoreMissingSplitsActivity', 'com.google.android.play.core.common.PlayCoreDialogWrapperActivity', 'com.google.android.gms.common.api.GoogleApiActivity']

Activities

Information computed with AndroGuard.

in.workindia.nileshdungarwal.workindiaandroid.AnyJobActivity
in.workindia.nileshdungarwal.workindiaandroid.ChromeCustomTabActivity
in.workindia.nileshdungarwal.workindiaandroid.ServicesActivity
in.workindia.nileshdungarwal.workindiaandroid.JobBoxActivity
in.workindia.nileshdungarwal.workindiaandroid.AccountSettingActivity
in.workindia.nileshdungarwal.workindiaandroid.CompanyFeedbackActivity
in.workindia.nileshdungarwal.workindiaandroid.EmployerUnlockedJobsActivity
in.workindia.nileshdungarwal.workindiaandroid.AutofillCityActivity
in.workindia.nileshdungarwal.workindiaandroid.ProfileSettingsActivity
in.workindia.nileshdungarwal.workindiaandroid.SearchActivity
in.workindia.nileshdungarwal.workindiaandroid.SplashScreenActivity
in.workindia.nileshdungarwal.workindiaandroid.RegisterActivity
in.workindia.nileshdungarwal.workindiaandroid.BlankBranchShareActivity
in.workindia.nileshdungarwal.workindiaandroid.StreamingMp3PlayerActivity
in.workindia.nileshdungarwal.workindiaandroid.PlayMediaActivity
in.workindia.nileshdungarwal.workindiaandroid.FavoriteJobListActivity
in.workindia.nileshdungarwal.workindiaandroid.ProfileEditActivity
in.workindia.nileshdungarwal.workindiaandroid.ProfilePageActivity
in.workindia.nileshdungarwal.workindiaandroid.JobLongDescriptionActivity
in.workindia.nileshdungarwal.workindiaandroid.goverment_jobs.GovernmentJobLongDescriptionActivity
in.workindia.nileshdungarwal.workindiaandroid.AppliedJobsActivity
in.workindia.nileshdungarwal.workindiaandroid.LanguageActivity
in.workindia.nileshdungarwal.workindiaandroid.LanguageActivityNew
in.workindia.nileshdungarwal.workindiaandroid.SettingsActivity
in.workindia.nileshdungarwal.workindiaandroid.NotificationListActivity
in.workindia.nileshdungarwal.workindiaandroid.FilterActivity
in.workindia.nileshdungarwal.workindiaandroid.MultipleJobViewActivity
in.workindia.nileshdungarwal.workindiaandroid.InterviewTipActivity
in.workindia.nileshdungarwal.workindiaandroid.FirstFillProfileActivity
in.workindia.nileshdungarwal.workindiaandroid.AmezingShare
in.workindia.nileshdungarwal.workindiaandroid.RecommendedJobActivityV2
in.workindia.nileshdungarwal.workindiaandroid.CreateResumeActivity
in.workindia.nileshdungarwal.workindiaandroid.GovernmentJobActivity
in.workindia.nileshdungarwal.workindiaandroid.ShareContactActivity
in.workindia.nileshdungarwal.workindiaandroid.ShareActivity
in.workindia.nileshdungarwal.workindiaandroid.JobAddressActivity
in.workindia.nileshdungarwal.workindiaandroid.SkillQuestionActivity
in.workindia.nileshdungarwal.workindiaandroid.AddSkillActivity
in.workindia.nileshdungarwal.workindiaandroid.SearchSkillActivity
in.workindia.nileshdungarwal.workindiaandroid.UploadResumePhotoActivity
in.workindia.nileshdungarwal.workindiaandroid.CityActivity
in.workindia.nileshdungarwal.workindiaandroid.RecordVoiceActivity
in.workindia.nileshdungarwal.workindiaandroid.WriteReviewActivity
in.workindia.nileshdungarwal.workindiaandroid.FillJobTitleExperienceActivity
in.workindia.nileshdungarwal.workindiaandroid.WorkindiaProfileActivity
in.workindia.nileshdungarwal.workindiaandroid.EmployerLeadActivity
in.workindia.nileshdungarwal.workindiaandroid.WorkindiaJobWebActivity
in.workindia.nileshdungarwal.workindiaandroid.SelectSectorActivity
in.workindia.nileshdungarwal.workindiaandroid.LoginActivity
in.workindia.nileshdungarwal.workindiaandroid.WebViewActivity
in.workindia.nileshdungarwal.workindiaandroid.ResumeBuilderActivity
in.workindia.nileshdungarwal.workindiaandroid.HelpAndSupportActivity
in.workindia.nileshdungarwal.workindiaandroid.VerifyOtpActivity
in.workindia.nileshdungarwal.workindiaandroid.MainActivityListV2
in.workindia.nileshdungarwal.workindiaandroid.ProfileEditNewActivity
in.workindia.nileshdungarwal.workindiaandroid.nps.NpsResponseReasonActivity
com.theartofdev.edmodo.cropper.CropImageActivity
com.facebook.FacebookActivity
com.facebook.CustomTabMainActivity
com.facebook.CustomTabActivity
com.google.android.libraries.places.widget.AutocompleteActivity
com.google.android.gms.auth.api.signin.internal.SignInHubActivity
pub.devrel.easypermissions.AppSettingsDialogHolderActivity
com.google.android.play.core.missingsplits.PlayCoreMissingSplitsActivity
com.google.android.play.core.common.PlayCoreDialogWrapperActivity
com.google.android.gms.common.api.GoogleApiActivity

Receivers

Information computed with AndroGuard.

in.workindia.nileshdungarwal.recievers.CampaignReceiver
in.workindia.nileshdungarwal.recievers.LocationBroadcastReceiver
com.google.android.gms.analytics.CampaignTrackingReceiver
in.workindia.nileshdungarwal.recievers.CustomNotificationReceiver
in.workindia.nileshdungarwal.recievers.yesnorecievers.CancelNotificationResponse
in.workindia.nileshdungarwal.recievers.yesnorecievers.YesNoPositiveResponse
in.workindia.nileshdungarwal.recievers.yesnorecievers.YesNoNegativeResponse
in.workindia.nileshdungarwal.recievers.yesnorecievers.YesNoCancelResponse
in.workindia.nileshdungarwal.recievers.PeriodicLocationStart
in.workindia.nileshdungarwal.recievers.ScheduleNotification
in.workindia.nileshdungarwal.recievers.PhoneHangupReceiver
in.workindia.nileshdungarwal.recievers.MySmsReceiver
com.google.android.gms.analytics.AnalyticsReceiver
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
com.facebook.CampaignTrackingReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver
com.google.android.gms.measurement.AppMeasurementReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver

Services

Information computed with AndroGuard.

in.workindia.nileshdungarwal.workindiaandroid.mvvm.utils.services.VideoUploadService
in.workindia.nileshdungarwal.services.MyFcmMessageListenerService
in.workindia.nileshdungarwal.services.CallOverlayService
in.workindia.nileshdungarwal.services.SmsSender
in.workindia.nileshdungarwal.services.LocationService
in.workindia.nileshdungarwal.services.StopLocationUploadService
in.workindia.nileshdungarwal.services.LocalSortService
in.workindia.nileshdungarwal.services.MediaPlayerService
in.workindia.nileshdungarwal.services.CheckMediaPlayerService
in.workindia.nileshdungarwal.services.LocalContactStoreService
in.workindia.nileshdungarwal.services.CollectIdService
in.workindia.nileshdungarwal.services.AddJobsJsonIntentService
in.workindia.nileshdungarwal.services.AddOtherJsonIntentService
in.workindia.nileshdungarwal.sync.SyncService
in.workindia.nileshdungarwal.sync.AccountAuthenticatorService
com.google.android.gms.analytics.AnalyticsService
in.workindia.nileshdungarwal.services.CallLogIntentService
com.google.firebase.components.ComponentDiscoveryService
com.google.android.gms.analytics.AnalyticsJobService
com.google.android.gms.auth.api.signin.RevocationBoundService
com.google.firebase.messaging.FirebaseMessagingService
com.google.android.play.core.assetpacks.AssetPackExtractionService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService

Sample timeline

Certificate valid not before June 28, 2015, 4:40 p.m.
First submission on VT Aug. 21, 2021, 6:51 a.m.
Last submission on VT Aug. 21, 2021, 6:51 a.m.
Upload on Pithus Aug. 21, 2021, 6:53 a.m.
Certificate valid not after June 21, 2040, 4:40 p.m.

NIAP analysis

Information computed with MobSF.

FCS_RBG_EXT.1.1 The application invoke platform-provided DRBG functionality for its cryptographic operations.
Random Bit Generation Services
FCS_STO_EXT.1.1 The application does not store any credentials to non-volatile memory.
Storage of Credentials
FCS_CKM_EXT.1.1 The application generate no asymmetric cryptographic keys.
Cryptographic Key Generation Services
FDP_DEC_EXT.1.1 The application has access to ['location', 'network connectivity', 'microphone', 'camera'].
Access to Platform Resources
FDP_DEC_EXT.1.2 The application has access to ['calender', 'call lists', 'address book'].
Access to Platform Resources
FDP_NET_EXT.1.1 The application has user/application initiated network communications.
Network Communications
FDP_DAR_EXT.1.1 The application does not encrypt files in non-volatile memory.
Encryption Of Sensitive Application Data
FMT_MEC_EXT.1.1 The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options.
Supported Configuration Mechanism
FTP_DIT_EXT.1.1 The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product.
Protection of Data in Transit
FCS_RBG_EXT.2.1
FCS_RBG_EXT.2.2
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate.
Random Bit Generation from Application
FCS_CKM.1.1(1) The application generate asymmetric cryptographic keys not in accordance with FCS_CKM.1.1(1) using key generation algorithm RSA schemes and cryptographic key sizes of 1024-bit or lower.
Cryptographic Asymmetric Key Generation
FCS_COP.1.1(2) The application perform cryptographic hashing services not in accordance with FCS_COP.1.1(2) and uses the cryptographic algorithm RC2/RC4/MD4/MD5.
Cryptographic Operation - Hashing
FCS_COP.1.1(3) The application perform cryptographic signature services (generation and verification) in accordance with a specified cryptographic algorithm RSA schemes using cryptographic key sizes of 2048-bit or greater.
Cryptographic Operation - Signing
FCS_COP.1.1(4) The application perform keyed-hash message authentication with cryptographic algorithm ['HMAC-SHA-256'] .
Cryptographic Operation - Keyed-Hash Message Authentication
FCS_HTTPS_EXT.1.1 The application implement the HTTPS protocol that complies with RFC 2818.
HTTPS Protocol
FCS_HTTPS_EXT.1.2 The application implement HTTPS using TLS.
HTTPS Protocol
FCS_HTTPS_EXT.1.3 The application notify the user and not establish the connection or request application authorization to establish the connection if the peer certificate is deemed invalid.
HTTPS Protocol
FIA_X509_EXT.2.1 The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS.
X.509 Certificate Authentication
FPT_TUD_EXT.2.1 The application shall be distributed using the format of the platform-supported package manager.
Integrity for Installation and Update

Code analysis

Information computed with MobSF.

Low
CVSS:7.5
The App logs information. Sensitive information should never be logged.
MASVS: MSTG-STORAGE-3
CWE-532 Insertion of Sensitive Information into Log File
Files:
 e/a/a/h/View$OnClickListenerC1250ga.java
d/f/a/e/h/i/ra.java
d/f/a/e/d/s.java
b/n/a/C0263c.java
b/n/a/B.java
e/a/a/q/C1351d.java
d/b/a/c/d/e/j.java
d/f/b/d/a/f.java
e/a/a/r/f/b/k.java
d/d/d/ca.java
d/f/a/f/s/d.java
d/f/b/i/y.java
b/p/a/a.java
e/a/a/d/h.java
b/b/g/X.java
d/b/a/c/a/a/d.java
in/workindia/nileshdungarwal/workindiaandroid/fragments/FragWallFriends.java
b/b/b/a/a.java
e/a/a/q/D.java
e/a/a/r/b/Bd.java
e/a/a/r/b/Za.java
e/a/a/r/d/a/e.java
d/f/b/k/b/e.java
in/workindia/nileshdungarwal/workindiaandroid/fragments/FragProfilePageDisplay.java
d/f/a/e/e/f/a.java
e/a/a/r/d/G.java
d/b/a/d/f.java
e/a/a/r/b/Oc.java
org/xbill/DNS/Client.java
e/a/a/h/C.java
in/workindia/nileshdungarwal/workindiaandroid/NotificationListActivity.java
in/workindia/nileshdungarwal/services/LocalSortService.java
com/exotel/verification/NumberHelper.java
d/f/b/d/a/k/a.java
e/a/a/h/View$OnClickListenerC1238dd.java
b/b/f/f.java
e/a/a/q/b/b.java
d/d/L.java
e/a/a/q/S.java
e/a/a/r/c/z.java
b/i/i/AbstractC0257b.java
b/b/g/ra.java
d/f/a/e/e/a/a/M.java
e/a/a/a/Z.java
d/b/a/c/d/a/n.java
d/f/a/e/e/e.java
d/f/b/m/u.java
b/k/b/i.java
e/a/a/o/k.java
d/b/a/c/b/L.java
e/a/a/r/j/X.java
b/n/a/F.java
d/d/a/b/k.java
b/g/c/c.java
d/b/a/c/b/t.java
d/b/a/c/b/C0347l.java
b/b/g/ta.java
d/f/b/d/a/c/Z.java
d/f/b/i/E.java
in/workindia/nileshdungarwal/recievers/PeriodicLocationStart.java
d/f/b/d/a/k/e.java
d/b/a/d/n.java
d/f/a/e/h/l/Na.java
d/f/a/f/v/j.java
d/a/d/a/k.java
e/a/a/r/c/r.java
b/m/a/b.java
in/workindia/nileshdungarwal/custom_view/SimpleTooltip.java
m/a/a/a/c.java
d/f/a/e/a/l.java
d/f/a/e/h/l/Tb.java
d/d/C0394e.java
d/f/a/g/a/c/C1034e.java
d/f/b/m/r.java
d/f/a/e/d/C0482d.java
in/workindia/nileshdungarwal/recievers/yesnorecievers/YesNoNegativeResponse.java
d/f/b/d/a/c/C1055h.java
d/f/b/d/a/b.java
d/b/a/c/c/C0352e.java
b/b/f/a/h.java
com/exotel/verification/a.java
d/b/a/c/b/A.java
e/a/a/q/V.java
e/a/a/m/e.java
d/f/b/d.java
in/workindia/nileshdungarwal/services/CheckMediaPlayerService.java
b/i/a/f.java
b/b/g/C0219aa.java
d/d/a/b/a/d.java
d/f/a/e/e/p.java
d/f/a/e/d/e.java
in/workindia/nileshdungarwal/workindiaandroid/mvvm/ui/navigation/resume/ResumeFragment$initialize$$inlined$let$lambda$2.java
d/f/a/e/d/AbstractC0480b.java
b/d/a/j.java
d/d/a/E.java
b/g/c/d.java
d/f/b/o/a/o.java
in/workindia/nileshdungarwal/custom_view/OverlayView.java
d/f/a/e/e/g/j.java
d/b/a/c/b/b/j.java
d/d/P.java
d/f/a/g/a/c/A.java
in/workindia/nileshdungarwal/workindiaandroid/fragments/FragCreateResume.java
e/a/a/r/b/Cc.java
d/f/a/e/e/a/a/U.java
in/workindia/nileshdungarwal/workindiaandroid/fragments/FragJobShareFriends.java
d/f/b/i/v.java
in/workindia/nileshdungarwal/utility/LinearLayoutManagerWrapper.java
d/f/a/e/h/l/sg.java
e/a/a/r/d/ViewTreeObserver$OnGlobalLayoutListenerC1611e.java
d/f/a/b/b/a/i.java
d/b/a/c/a/k.java
d/d/a/b/l.java
e/a/a/m/h.java
com/exotel/verification/d.java
d/b/a/c/d/a/k.java
d/f/a/e/l/a/a.java
d/f/b/d/a/c/U.java
com/exotel/verification/Utils.java
d/b/a/d/g.java
in/workindia/nileshdungarwal/recievers/yesnorecievers/CancelNotificationResponse.java
d/f/b/d/a/c/aa.java
e/a/a/r/RunnableC1696qb.java
d/f/a/e/e/c/M.java
e/a/a/r/C1694q.java
d/f/a/h/a/a/l.java
b/l/e.java
d/f/b/d/a/c/S.java
d/f/a/f/a/g.java
in/workindia/nileshdungarwal/services/MediaPlayerService.java
com/exotel/verification/f.java
d/f/a/f/t/b.java
d/f/b/m/C1094a.java
e/a/a/a/P.java
d/f/b/d/a/c/CallableC1064q.java
e/a/a/h/RunnableC1247fc.java
in/workindia/nileshdungarwal/workindiaandroid/SplashScreenActivity.java
b/i/c/d.java
f/a/b/y.java
d/f/b/i/o.java
d/l/a/a/c.java
d/f/a/e/h/h/h.java
e/a/a/q/Y.java
d/d/a/b/j.java
in/workindia/nileshdungarwal/recievers/ScheduleNotification.java
e/a/a/o/s.java
d/d/a/n.java
b/n/a/LayoutInflater$Factory2C0283x.java
b/r/b/f.java
d/d/a/c/o.java
e/a/a/r/b/Ib.java
b/i/c/f.java
e/a/a/h/Ea.java
d/f/a/e/d/v.java
d/f/a/e/e/a/a/RunnableC0489ca.java
d/f/b/d/a/i.java
in/workindia/nileshdungarwal/services/CollectIdService.java
d/b/a/c/d/a/t.java
d/b/a/c/b/a/k.java
d/f/b/m/q.java
e/a/a/r/b/Ac.java
e/a/a/r/Aa.java
e/a/a/c/a.java
d/b/a/c/c/i.java
e/a/a/q/T.java
d/b/a/c/b/b/e.java
d/f/a/e/h/l/Aa.java
d/f/b/m/A.java
d/f/a/e/e/w.java
b/i/h/a.java
com/exotel/verification/RequestHelper.java
e/a/a/j/g.java
d/f/a/e/e/c/BinderC0536a.java
d/b/a/c/d/c.java
d/b/a/c/a/m.java
d/d/d/a/a/c.java
d/f/a/e/e/a/a/C0533z.java
d/f/b/k/a/c.java
b/i/a/q.java
e/a/a/j/p.java
d/f/b/d/a/c/N.java
d/b/a/c/c/A.java
d/f/a/b/b/c/b/f.java
d/f/a/e/e/a/a/C0526va.java
e/a/a/m/f.java
e/a/a/r/RunnableC1452ab.java
in/workindia/nileshdungarwal/retrofit/RetroServiceGenerator.java
b/i/i/E.java
d/f/b/m/D.java
d/f/a/e/e/a/a/BinderC0517qa.java
e/a/a/r/d/a/j.java
org/xbill/DNS/SimpleResolver.java
d/f/a/f/w/j.java
b/i/i/i.java
in/workindia/nileshdungarwal/workindiaandroid/GovernmentJobActivity.java
d/f/b/c/h.java
b/s/a/b.java
b/i/e/g.java
d/f/b/i/r.java
e/a/a/r/b/A.java
b/g/c/b.java
d/b/a/d/l.java
com/exotel/verification/i.java
b/t/a/C0305u.java
in/workindia/nileshdungarwal/workindiaandroid/StartApplication.java
in/workindia/nileshdungarwal/workindiaandroid/AmezingShare.java
e/a/a/r/Ba.java
b/b/f/a/k.java
d/f/b/o/f.java
d/f/b/i/f.java
defpackage/d.java
e/a/a/r/Pb.java
e/a/a/r/j/C1656o.java
org/xbill/DNS/TSIG.java
d/f/a/e/h/l/Ea.java
e/a/a/r/Nb.java
in/workindia/nileshdungarwal/workindiaandroid/MainActivityListV2.java
in/workindia/nileshdungarwal/workindiaandroid/BlankBranchShareActivity.java
d/f/b/i/B.java
b/b/a/E.java
d/b/a/c/c/z.java
d/b/a/d/q.java
b/b/a/J.java
d/a/d/y.java
d/b/a/b/d.java
d/f/a/e/h/i/C0569ea.java
e/a/a/q/ra.java
d/f/a/e/e/c/AbstractDialogInterface$OnClickListenerC0553s.java
d/f/a/h/a/i.java
d/d/e/E.java
b/g/b/d.java
e/a/a/o/i.java
com/theartofdev/edmodo/cropper/CropImageActivity.java
e/a/a/d/d.java
in/workindia/nileshdungarwal/recievers/yesnorecievers/YesNoPositiveResponse.java
e/a/a/o/u.java
b/i/b/a.java
in/workindia/nileshdungarwal/workindiaandroid/LoginActivity.java
d/f/b/o/a/f.java
d/b/a/i/a/d.java
e/a/a/q/AbstractC1364q.java
b/i/c/k.java
d/d/d/G.java
b/b/g/C.java
d/f/a/e/h/l/C0699oc.java
e/a/a/q/F.java
com/exotel/verification/ConfigBuilder.java
d/b/a/h/b.java
in/workindia/nileshdungarwal/services/AddJobsJsonIntentService.java
d/b/a/c/d/a/B.java
d/b/a/d/e.java
d/f/a/e/e/f/c.java
d/f/a/f/q/d.java
b/i/c/a/g.java
e/a/a/m/g.java
d/f/a/e/e/c/C0558x.java
b/i/c/c.java
in/workindia/nileshdungarwal/sync/SyncService.java
e/a/a/q/C1365s.java
com/exotel/verification/c.java
b/n/a/ActivityC0271k.java
d/f/b/d/a/i/b/c.java
e/a/a/r/b/C1490fe.java
in/workindia/nileshdungarwal/recievers/yesnorecievers/YesNoCancelResponse.java
d/f/a/e/h/l/C0648h.java
d/f/a/e/e/c/N.java
b/i/i/C0256a.java
d/d/ca.java
in/workindia/nileshdungarwal/models/EmployeeProfile.java
e/a/a/a/fa.java
d/f/a/e/e/d/a.java
in/workindia/nileshdungarwal/services/MyFcmMessageListenerService.java
e/a/a/r/b/Gb.java
d/f/b/d/a/h.java
b/i/b/a/j.java
e/a/a/h/Ma.java
in/workindia/nileshdungarwal/workindiaandroid/AnyJobActivity.java
d/f/b/k/c.java
d/b/a/c/a/a/b.java
d/f/a/e/d/j.java
org/xbill/DNS/Lookup.java
in/workindia/nileshdungarwal/services/LocationService.java
e/a/a/r/d/E.java
b/i/i/w.java
d/d/d/Q.java
d/f/b/i/w.java
e/a/a/q/M.java
d/d/a/b/a/e.java
d/f/a/b/b/c/a/n.java
e/a/a/r/C1716vc.java
e/a/a/r/b/Ja.java
e/a/a/f/a.java
e/a/a/r/f/d/d.java
d/f/a/e/j/a/m.java
e/a/a/q/r.java
d/f/a/e/e/k.java
d/f/b/d/a/d/g.java
d/d/a/e/a.java
b/b/g/Z.java
d/f/a/e/e/a/a/Qa.java
d/f/b/d/a/k/b/d.java
e/a/a/r/d/C1609c.java
b/i/a/e.java
d/f/a/e/h/l/Oa.java
b/w/S.java
e/a/a/m/c.java
d/f/a/e/h/i/C0560a.java
e/a/a/q/C1356i.java
d/f/b/d/a/k/b/a.java
d/b/a/c/d/a/p.java
b/n/a/C0261a.java
d/f/a/f/v/i.java
d/b/a/c/d/a/C0355c.java
e/a/a/r/AbstractActivityC1690p.java
d/f/b/m/h.java
in/workindia/nileshdungarwal/dbhelper/DataProvider.java
e/a/a/h/Zc.java
d/b/a/c/b/RunnableC0346k.java
in/workindia/nileshdungarwal/services/LocalContactStoreService.java
e/a/a/g/a.java
e/a/a/p/c.java
e/a/a/r/b/C1504ia.java
d/f/a/e/e/c/AbstractC0545j.java
d/f/a/e/e/a/a/H.java
d/f/b/m/t.java
in/workindia/nileshdungarwal/workindiaandroid/ShareActivity.java
b/i/c/g.java
com/theartofdev/edmodo/cropper/CropOverlayView.java
e/a/a/r/b/Cd.java
d/b/a/g/a/i.java
in/workindia/nileshdungarwal/services/CallLogIntentService.java
in/workindia/nileshdungarwal/workindiaandroid/FirstFillProfileActivity.java
m/a/a/a/a.java
in/workindia/nileshdungarwal/workindiaandroid/ShareContactActivity.java
d/b/a/c/d/b.java
d/f/a/e/e/j.java
d/a/b/a/a.java
d/f/a/e/e/a/a/Ga.java
b/b/a/y.java
d/b/a/c/a/b.java
e/a/a/h/RunnableC1242ec.java
d/f/a/e/h/l/La.java
d/d/a/o.java
d/b/a/c/d/e/a.java
d/f/a/e/h/i/C0563ba.java
b/w/ca.java
b/b/g/La.java
e/a/a/q/C.java
e/a/a/q/b/a.java
d/f/a/e/e/g/d.java
e/a/a/r/b/C1527mb.java
in/workindia/nileshdungarwal/retrofit/RetrofitSyncAll.java
d/d/f/b/C0428k.java
b/b/g/L.java
d/j/a/a/U.java
in/workindia/nileshdungarwal/workindiaandroid/RegisterActivity.java
e/a/a/r/d/F.java
d/d/a/c/j.java
e/a/a/r/DialogInterface$OnClickListenerC1683na.java
d/f/a/e/e/a/a/C0496g.java
e/a/a/o/f.java
d/f/a/e/f/g.java
e/a/a/r/b/C1517kb.java
in/workindia/nileshdungarwal/workindiaandroid/CityActivity.java
e/a/a/r/C1720wc.java
b/i/g/b.java
f/a/b/C1737e.java
in/workindia/nileshdungarwal/recievers/CustomNotificationReceiver.java
d/f/a/e/e/c/AbstractC0537b.java
d/f/b/d/a/c/ga.java
com/edmodo/rangebar/RangeBar.java
e/a/a/r/b/Ra.java
d/f/b/i/x.java
d/b/a/c/d/a/F.java
d/f/b/m/z.java
d/f/a/e/h/j/s.java
e/a/a/j/r.java
d/f/a/e/h/l/C0668k.java
in/workindia/nileshdungarwal/workindiaandroid/MultipleJobViewActivity.java
d/b/a/c/b/c/d.java
in/workindia/nileshdungarwal/services/SmsSender.java
d/d/a/p.java
d/b/a/g/h.java
d/f/a/e/a/j.java
b/i/i/x.java
in/workindia/nileshdungarwal/models/Filter.java
d/f/a/e/e/a/e.java
d/b/a/b/e.java
b/b/g/Ia.java
b/b/g/P.java
e/a/a/q/G.java
d/f/b/d/a/i/b.java
e/a/a/o/j.java
d/d/a/c/b.java
e/a/a/r/b/C1572vc.java
e/a/a/q/C1358k.java
e/a/a/r/C1723xb.java
d/k/a/V.java
e/a/a/q/C1362o.java
d/f/a/e/b/a/c/a/g.java
b/w/ea.java
d/d/e/I.java
com/exotel/verification/DeviceInfoHelper.java
com/exotel/verification/ExotelVerification.java
b/w/P.java
d/f/a/e/e/q.java
d/f/a/e/h/l/Qa.java
d/f/a/e/k/b/C0900tb.java
e/a/a/q/RunnableC1354g.java
d/d/d/AbstractC0384p.java
org/xbill/DNS/spi/DNSJavaNameService.java
in/workindia/nileshdungarwal/recievers/PhoneHangupReceiver.java
d/b/a/c/c/f.java
org/xbill/DNS/ExtendedResolver.java
d/f/b/d/a/c/na.java
e/a/a/j/a.java
d/f/a/e/e/c/C0552q.java
in/workindia/nileshdungarwal/recievers/MySmsReceiver.java
d/b/a/c/d/e/d.java
d/b/a/c/b/a/j.java
d/d/d/ba.java
d/f/b/i/C.java
e/a/a/j/o.java
b/r/a/b.java
in/workindia/nileshdungarwal/services/AddOtherJsonIntentService.java
d/b/a/b.java
d/f/b/m/C1096c.java
d/d/d/T.java
d/f/a/e/m/a.java
b/i/a/u.java
d/b/a/n.java
e/a/a/d/c.java
d/f/a/e/b/a/c/a/e.java
b/x/a/a/j.java
e/a/a/r/b/C1521la.java
d/f/a/e/e/a/a/L.java
d/f/a/e/d/u.java
d/f/a/e/d/i.java
in/workindia/nileshdungarwal/recievers/CampaignReceiver.java
e/a/a/r/b/Ic.java
in/workindia/nileshdungarwal/utility/VideoEnabledWebView.java
e/a/a/o/c.java
e/a/a/q/fa.java
d/f/b/m/E.java
d/d/a/f.java
b/i/c/e.java
b/b/g/Fa.java
d/f/a/e/h/i/C0575j.java
d/j/a/a/aa.java
e/a/a/r/b/C1526ma.java
e/a/a/r/d/a/i.java
d/f/a/e/h/l/Ra.java
e/a/a/r/b/RunnableC1488fc.java
d/f/a/e/e/c/X.java
High
CVSS:5.5
App can read/write to External Storage. Any App can read data written to External Storage.
MASVS: MSTG-STORAGE-2
CWE-276 Incorrect Default Permissions
M2: Insecure Data Storage
Files:
 e/a/a/r/b/Ce.java
in/workindia/nileshdungarwal/workindiaandroid/mvvm/ui/navigation/resume/preview/ResumePreviewFragment.java
d/d/d/ba.java
e/a/a/r/g/c/b.java
e/a/a/r/b/Qd.java
e/a/a/q/fa.java
d/f/a/g/a/a/C1013ra.java
b/i/b/a.java
e/a/a/r/b/Md.java
e/a/a/q/V.java
Medium
CVSS:8.8
Insecure WebView Implementation. Execution of user controlled code in WebView is a critical Security Hole.
MASVS: MSTG-PLATFORM-7
CWE-749 Exposed Dangerous Method or Function
M1: Improper Platform Usage
Files:
 e/a/a/r/b/Ce.java
e/a/a/r/b/Lc.java
in/workindia/nileshdungarwal/workindiaandroid/fragments/FragWorkindiaProfile.java
High
CVSS:7.5
The App uses an insecure Random Number Generator.
MASVS: MSTG-CRYPTO-6
CWE-330 Use of Insufficiently Random Values
M5: Insufficient Cryptography
Files:
 d/f/a/e/h/l/C0616cc.java
d/f/a/e/h/l/Pc.java
d/f/a/e/h/l/Gc.java
f/b/e/j/k.java
d/f/a/e/h/l/Hd.java
d/f/a/e/h/l/Ad.java
d/f/a/e/h/c/a.java
d/f/b/o/a/m.java
d/f/a/e/k/b/ue.java
d/f/a/e/h/l/_c.java
h/a/i.java
d/f/a/e/h/l/_b.java
d/d/d/ba.java
d/f/a/e/h/l/AbstractC0760xb.java
d/f/b/d/a/e/P.java
org/xbill/DNS/Header.java
h/a/c.java
d/f/a/e/h/l/C0638fd.java
h/f/b.java
d/d/C0446q.java
d/f/a/e/h/l/Ud.java
com/fasterxml/jackson/databind/ser/BasicSerializerFactory.java
d/f/a/e/h/l/C0648h.java
d/f/b/o/o.java
d/f/a/e/h/l/C0733tc.java
d/f/a/e/h/l/Lc.java
k/s.java
h/f/a.java
High
CVSS:5.5
App creates temp file. Sensitive information should never be written into a temp file.
MASVS: MSTG-STORAGE-2
CWE-276 Incorrect Default Permissions
M2: Insecure Data Storage
Files:
 com/theartofdev/edmodo/cropper/CropImageActivity.java
d/l/a/a/c.java
d/f/b/k/a/d.java
e/a/a/q/V.java
Info
CVSS:0
This App uses SSL certificate pinning to detect or prevent MITM attacks in secure communication channel.
MASVS: MSTG-NETWORK-4
Files:
 in/workindia/nileshdungarwal/retrofit/RetroServiceGenerator.java
in/workindia/nileshdungarwal/workindiaandroid/mvvm/utils/retrofit/RetrofitHelper.java
j/a/h/h.java
j/a/h/g.java
d/e/a/c/a/a/v.java
Medium
CVSS:4.3
IP Address disclosure
MASVS: MSTG-CODE-2
CWE-200 Information Exposure
Files:
 e/a/a/r/b/Qd.java
in/workindia/nileshdungarwal/workindiaandroid/MainActivityListV2.java
in/workindia/nileshdungarwal/workindiaandroid/fragments/FragProfilePageDisplay.java
com/exotel/verification/d.java
e/a/a/h/View$OnClickListenerC1222ac.java
in/workindia/nileshdungarwal/models/JourneyHelper$Companion$getJourney$1.java
e/a/a/j/r.java
in/workindia/nileshdungarwal/models/JsonEmployeeProfile.java
e/a/a/q/D.java
com/exotel/verification/Utils.java
High
CVSS:5.9
SHA-1 is a weak hash known to have hash collisions.
MASVS: MSTG-CRYPTO-4
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
M5: Insufficient Cryptography
Files:
 org/xbill/DNS/NSEC3Record.java
d/f/b/k/a/c.java
d/f/b/d/a/c/C1055h.java
d/j/a/a/aa.java
org/xbill/DNS/DNSSEC.java
d/f/b/i/o.java
Info
CVSS:0
This App may have root detection capabilities.
MASVS: MSTG-RESILIENCE-1
Files:
 d/f/a/e/h/l/Na.java
d/f/b/d/a/c/C1055h.java
d/f/a/g/a/c/C1046q.java
High
CVSS:7.4
MD5 is a weak hash known to have hash collisions.
MASVS: MSTG-CRYPTO-4
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
M5: Insufficient Cryptography
Files:
 d/f/a/e/k/b/ue.java
d/d/a/f.java
f/a/a/d.java
High
CVSS:5.9
App uses SQLite Database and execute raw SQL query. Untrusted user input in raw SQL queries can cause SQL Injection. Also sensitive information should be encrypted and written to the database.
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
M7: Client Code Quality
Files:
 e/a/a/g/a.java
d/j/a/a/D.java
d/f/a/e/k/b/C0881pb.java
d/f/a/e/h/i/C0586v.java
d/j/a/a/A.java
d/f/a/e/k/b/C0856ke.java
in/workindia/nileshdungarwal/workindiaandroid/StartApplication.java
d/f/a/b/b/c/b/p.java
d/f/a/e/k/b/Fe.java
d/f/a/e/k/b/C0827g.java
in/workindia/nileshdungarwal/dbhelper/DataProvider.java
d/f/a/b/b/c/b/f.java
d/f/a/b/b/c/b/t.java
d/f/a/e/h/i/C0587w.java
d/f/a/b/b/c/b/v.java
Low
CVSS:0
This App copies data to clipboard. Sensitive data should not be copied to clipboard as other applications can access it.
MASVS: MSTG-STORAGE-10
Files:
 e/a/a/r/b/Lc.java
e/a/a/j/g.java
in/workindia/nileshdungarwal/workindiaandroid/fragments/FragWorkindiaProfile.java
High
CVSS:7.4
Insecure Implementation of SSL. Trusting all the certificates or accepting self signed certificates is a critical Security Hole. This application is vulnerable to MITM attacks
MASVS: MSTG-NETWORK-3
CWE-295 Improper Certificate Validation
M3: Insecure Communication
Files:
 j/a/h/a/b.java
High
CVSS:7.4
Files may contain hardcoded sensitive informations like usernames, passwords, keys etc.
MASVS: MSTG-STORAGE-14
CWE-312 Cleartext Storage of Sensitive Information
M9: Reverse Engineering
Files:
 d/b/a/c/b/z.java
Pygal Switzerland: 800 Germany: 500 Ireland: 100 India: 100 Netherlands: 100 Singapore: 100 United States: 2200

Map computed by Pithus.

Domains analysis

Information computed with MobSF.

US www.youtube.com 172.217.16.142
CH apps.workindia.in 13.224.96.115
US workindia-production-8f42d.firebaseio.com 35.201.97.85
CH api2.branch.io 13.224.96.98
DE api.branch.io 13.224.196.20
CH resources.workindia.in 13.224.96.82
US google.com 172.217.16.142
DE api.workindia.in 13.225.87.43
javax.xml.xmlconstants
CH fireanalytics.workindia.in 13.224.96.2
US ssl.google-analytics.com 142.250.185.232
SG notp.exotel.com 13.251.174.7
US s3.amazonaws.com 52.217.108.190
US sdk-api-v1.singular.net 184.25.51.73
graph-video.s
CH hire-tracking.workindia.in 13.224.96.62
reports.crashlytics.com
US www.google.com 142.250.185.228
US suggest.workindia.in 44.196.9.209
US maps.googleapis.com 142.250.185.106
graph.s
US accounts.google.com 172.217.16.141
IE exceptions.singular.net 34.253.101.70
IN s3.ap-south-1.amazonaws.com 52.219.156.53
CH api2.workindia.in 13.224.96.76
CH cdn.branch.io 13.224.96.63
live-location.workindia.in
ns.adobe.com
US update.crashlytics.com 142.250.184.195
US configurations.workindia.in 44.196.9.209
US www.googleadservices.com 142.250.184.226
US firebase.google.com 142.250.181.238
DE developers.facebook.com 31.13.92.10
US c.singular.net 184.25.51.11
US app-measurement.com 142.250.185.174
DE facebook.com 31.13.92.36
US play.google.com 142.250.74.206
US www.google-analytics.com 142.250.185.142
.facebook.com
US plus.google.com 216.58.212.142
NL upload.wikimedia.org 91.198.174.208
US goo.gl 142.250.185.174
CH www.workindia.in 13.224.96.60
US github.com 140.82.121.4
US developer.android.com 142.250.181.238
DE api.whatsapp.com 31.13.92.52

URL analysis

Information computed with MobSF.

https://upload.wikimedia.org/wikipedia/commons/6/6c/Grieg_Lyric_Pieces_Kobold.ogg
Defined in in/workindia/nileshdungarwal/workindiaandroid/PlayMediaActivity.java
https://play.google.com/store/apps/details?id=in.workindia.nileshdungarwal.workindiaandroid&hl=en
Defined in in/workindia/nileshdungarwal/workindiaandroid/NotificationListActivity.java
https://www.workindia.in/dl/job-share
Defined in in/workindia/nileshdungarwal/workindiaandroid/fragments/FragJobShareFriends.java
https://www.workindia.in/app/
Defined in in/workindia/nileshdungarwal/workindiaandroid/fragments/FragWorkindiaProfile.java
https://resources.workindia.in/candidate_profile/media/resume_video.gif
Defined in in/workindia/nileshdungarwal/workindiaandroid/mvvm/ui/navigation/resume/video/VideoResumeBottomSheet.java
https://api.workindia.in/
Defined in in/workindia/nileshdungarwal/workindiaandroid/mvvm/utils/retrofit/RetrofitHelper.java
https://resources.workindia.in/android/v1/assets/img/banner_become_gold_member.png
https://s3.amazonaws.com/prod-workindia-app-data/workindia-ecosystem/post_images/fraud_calls.png
Defined in in/workindia/nileshdungarwal/recievers/ScheduleNotification.java
https://hire-tracking.workindia.in/hire-tracking/call-list?data=
https://www.workindia.in/shareandwin/?app_version=501&language=
http://apps.workindia.in/learn/index.html?name=
Defined in in/workindia/nileshdungarwal/retrofit/UrlConstant.java
https://api2.workindia.in/
https://api.workindia.in/
https://maps.googleapis.com/
https://s3.amazonaws.com/
https://suggest.workindia.in/
Defined in in/workindia/nileshdungarwal/retrofit/RetroServiceGenerator.java
https://resources.workindia.in/android/v1/assets/translations/audio/iv_tip_
https://s3.amazonaws.com/prod-workindia-app-data/adhoc-images/img_app_share_banner.png
Defined in in/workindia/nileshdungarwal/retrofit/RetrofitSyncAll.java
https://api.workindia.in/api/candidate/profile/login/contact-verification/generate-code/
https://resources.workindia.in/android/v1/assets/configuration/update_config_v2.json
https://configurations.workindia.in/api/EntityConfigs/config
https://api.workindia.in/api/chat-bot-hiretracking/api/get_chatform
https://api.workindia.in/api/candidate/profile/candidate-profile/
https://api.workindia.in/api/candidate/profile/status/candidate-profile/
https://api.workindia.in/api/candidate/chat-bot/get_chatform
https://resources.workindia.in/android/v1/assets/translations/city/{city_name}.json
https://api.workindia.in/api/ratings-ms/v1/company/summary/
https://api.workindia.in/api/candidate/profile/candidate-configuration-v2/
https://resources.workindia.in/android/v1/assets/configuration/generic_popup_info.json
https://api.workindia.in/api/govjobs/get_jobs
https://api.workindia.in/api/govjobs/get_job_detail/
https://api.workindia.in/api/jobs/detail/
https://api.workindia.in/api/jobs/
https://api.workindia.in/api/jobs/count/
https://api.workindia.in/api/hiretracking/get-job-card/
https://api.workindia.in/api/nps/candidate/get-questions/5/
https://api2.workindia.in/api/mobile/v12/get-nearest-city-location/
https://api.workindia.in/api/jobs/old-expired/
https://resources.workindia.in/android/v1/assets/configuration/rate_your_call_options_config.json
https://api.workindia.in/api/jobs/recommended/
https://api.workindia.in/api/candidate/profile/sectors/job-filter/
https://api.workindia.in/api/suggest/generic-keyword/
https://resources.workindia.in/android/v1/assets/configuration/services_config.json
https://resources.workindia.in/android/v1/assets/configuration/share_n_win_config.json
https://api.workindia.in/api/jobs/similar/
https://resources.workindia.in/android/v1/assets/configuration/sector_questions.json
https://api.workindia.in/api/candidate/profile/login/
https://api.workindia.in/api/candidate/profile/upgrade/
https://api.workindia.in/api/candidate-events/events/app-open-data/
https://configurations.workindia.in/api/Entities/register/
https://api.workindia.in/api/candidate/profile/sectors/skills/update/prompt/
https://api.workindia.in/api/ratings-ms/v1/posts/
https://api.workindia.in/api/candidate/profile/register/
https://api.workindia.in/api/candidate-events/events/employer-duration-details/
https://api.workindia.in/api/candidate-events/events/job-applied/
https://api.workindia.in/api/candidate-events/events/employer-contacted-during-blackout/
https://api.workindia.in/api/candidate-events/events/job-fav/
https://api.workindia.in/api/candidate-events/events/employer-contacted/
https://api.workindia.in/api/candidate-events/events/otp-generate/
https://api.workindia.in/api/candidate-events/events/otp-verified/
https://api.workindia.in/api/candidate-events/events/final-stage-b4-call/
https://api.workindia.in/api/candidate-events/events/sms-sent/
https://api.workindia.in/api/candidate-events/events/employer-contacted-tried/
https://api.workindia.in/api/candidate-events/events/job-viewed/
https://live-location.workindia.in/candidate-location-collect-v2/
https://fireanalytics.workindia.in/log_event/
https://api.workindia.in/api/nps/candidate/save-responses/
https://api.workindia.in/api/candidate-connections/api/upload-contacts/
https://api.workindia.in/api/candidate/profile/update/candidate-configuration-v2/
https://api.workindia.in/api/candidate/profile/delete-profile/
https://api.workindia.in/api/candidate/profile/update/device-configuration/
https://api.workindia.in/api/candidate/profile/update/candidate-profile/
https://api.workindia.in/api/hiretracking/post-action/
https://api.workindia.in/api/hiretracking/candidate-location-track/
https://api.workindia.in/api/snw-coupon/api/referral_code_check/
https://api.workindia.in/api/candidate/profile/login/verify-number/
https://api.workindia.in/api/candidate/profile/login/contact-verification/verify-code/
https://api.workindia.in/api/candidate/profile/login/contact-verification/verify-call/
Defined in in/workindia/nileshdungarwal/retrofit/RestApi.java
https://developers.facebook.com/docs/app-events/getting-started-app-events-android#disable-auto-events.
Defined in d/d/ca.java
https://facebook.com
https://.facebook.com
Defined in d/d/d/ba.java
https://developers.facebook.com/docs/android/getting-started
https://developers.facebook.com/docs/sharing/android
Defined in d/d/d/ca.java
https://graph.%s
https://graph-video.%s
Defined in d/d/d/X.java
https://facebook.com/device?user_code=%1$s&qr=1
Defined in d/d/e/C0398d.java
https://update.crashlytics.com/spi/v1/platforms/android/apps
https://update.crashlytics.com/spi/v1/platforms/android/apps/%s
https://reports.crashlytics.com/spi/v1/platforms/android/apps/%s/reports
https://reports.crashlytics.com/sdk-api/v1/platforms/android/apps/%s/minidumps
Defined in d/f/b/d/a/k/i.java
https://firebase.google.com/support/privacy/init-options.
Defined in d/f/b/k/h.java
https://%s/%s/%s
Defined in d/f/b/k/b/e.java
https://developer.android.com/reference/com/google/android/play/core/assetpacks/model/AssetPackErrorCode.html#
Defined in d/f/a/g/a/a/C0979a.java
https://www.workindia.in/app-share
https://www.workindia.in/ref/
https://www.workindia.in/candidate/
https://api.whatsapp.com/send?phone=
Defined in d/f/a/f/v/j.java
https://plus.google.com/
Defined in d/f/a/e/e/c/O.java
https://accounts.google.com/o/oauth2/revoke?token=
Defined in d/f/a/e/b/a/c/a/e.java
http://goo.gl/8Rd3yj
Defined in d/f/a/e/h/i/B.java
http://goo.gl/8Rd3yj
Defined in d/f/a/e/h/i/ia.java
http://www.google-analytics.com
https://ssl.google-analytics.com
Defined in d/f/a/e/h/i/T.java
http://goo.gl/8Rd3yj
Defined in d/f/a/e/h/i/C0589y.java
http://goo.gl/naFqQk
Defined in d/f/a/e/h/i/C0566d.java
https://goo.gl/J1sWQy
Defined in d/f/a/e/h/l/C0648h.java
https://app-measurement.com/a
Defined in d/f/a/e/h/l/Fe.java
www.google.com
https://www.google.com
https://goo.gl/NAOOOI.
https://goo.gl/NAOOOI
https://www.googleadservices.com/pagead/conversion/app/deeplink?id_type=adid&sdk_version=%s&rdid=%s&bundleid=%s&retry=%s
Defined in d/f/a/e/k/b/ue.java
https://google.com/search?
Defined in d/f/a/e/k/b/_c.java
https://firebase.google.com/support/guides/disable-analytics
Defined in d/f/a/e/k/b/C0886qb.java
https://app-measurement.com/a
Defined in d/f/a/e/k/b/C0893s.java
http://play.google.com/store/apps/details
Defined in d/f/a/h/a/a/r.java
https://exceptions.singular.net/v2/exceptions/android
Defined in d/j/a/a/J.java
https://sdk-api-v1.singular.net/api/v1
Defined in d/j/a/a/AbstractC1154n.java
data:image
Defined in d/b/a/c/c/h.java
data:image
Defined in d/b/a/c/c/g.java
http://localhost/
Defined in retrofit2/Response.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
Defined in f/b/h.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
Defined in f/b/f.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
Defined in f/b/b.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
Defined in f/b/u.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
Defined in f/b/l.java
https://github.com/ReactiveX/RxJava/wiki/What's-different-in-2.0#error-handling
Defined in f/b/c/e.java
https://github.com/ReactiveX/RxJava/wiki/Error-Handling
Defined in f/b/c/c.java
https://api2.branch.io/
https://api.branch.io/
Defined in f/a/b/y.java
https://cdn.branch.io/sdk/uriskiplist_v#.json
Defined in f/a/b/T.java
https://c.singular.net/api/v1/ad?st=305913204341&h=1235ee5bc09560647ece479113296ea57f0ae89c