Reason Labs

findit.xml

The file findit.xml has been detected as malware named Hijacker.SnapDo.Search. This is a Mozilla Firefox web browser search plugin called ‘findit’ which enables the search engine provider as well as search suggestions.
MD5:
02c32586220a5930c39295e4ace54590

SHA-1:
345213ec97e147a11be5f1211440cbaf8c5e689b

SHA-256:
253e9af15e1373bfd0454fd92fa54097e9c7dd53e57f9e1426dd20ad863db9f6

Detection:
Hijacker.SnapDo.Search

Risk:
Medium

Explanation:
This potentially unwanted findit search plugin for Firefox is used to direct web searches from the search bar and runs as the browser's search engine.

Analysis date:
12/12/2018 11:31:00 AM UTC  (today)

File size:
2.3 KB (2,397 bytes)

File type:
OpenSearch plugin for Firefox

Common path:
C:\users\{user}\appdata\roaming\mozilla\firefox\profiles\{user}.default\searchplugins\findit.xml

Mozilla Search Plugins
Name:
findit

Description:
findit description

Search Form:
search.snap.do

Search Template:
http://feed.sonic-search.com/


<SearchPlugin xmlns="http://www.mozilla.org/2006/browser/search/">
  <ShortName>findit</ShortName>
  <Description>findit description</Description>
  <InputEncoding>UTF-8</InputEncoding>
  <Image width="16" height="16">data:image/x-icon;base64,{removed}</Image>
  <Url type="application/x-suggestions+json" method="GET" template="http://suggestqueries.google.com/complete/search?output=firefox&amp;client=firefox&amp;hl={moz:locale}&amp;q={searchTerms}" />
  <Url type="text/html" method="GET" template="http://feed.sonic-search.com/">
    <Param name="p" value="mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHza9wkcS1AcGjvM8blLr6iYRNxvsUIgmd58xLXY2PDIaOxwv77u_syOaIylD8wO2Dm94QvY8g_UgXlyW0k6jPv-uz9OzDkL6sRrj5fx0vLkRJ9mzhl6B_a6mdv5sbUeBVUY3VPi0jilCAJAGNt_CrHwIM1JGj8h56IePIO_KQ,," />
    <Param name="q" value="{searchTerms}" />
    <MozParam name="client" condition="defaultEngine" trueValue="firefox-a" falseValue="firefox" />
  </Url>
  <SearchForm>search.snap.do</SearchForm>
</SearchPlugin>
Download Reason Core Security - Powerful anti-malware software